Live data from Hacker News

Viewing profile — ohmygodel

ohmygodel

HN member
Joined
Mon, Sep 20, 2010, 2:05 AM UTC
HN karma
340
Public activity
52 items

About ohmygodel

No profile information was provided.

Recent public activity

  1. comment
    Comment #22297737

    Yes, if you manually and wisely choose your own guard nodes, then you can avoid these attacks. You should be sure that those guards can't themselves be linked to you, either.

  2. comment
    Comment #22295649

    I assume you refer to [0]. He says "If [the adversary] can knock me off enough guards, my tor daemon will eventually choose one of his guards. Then he can identify my actual networ…

  3. comment
    Comment #22294946

    The Tor protocol doesn't explicitly signal the guard relay that it is in the guard position. However, the guard relay (call it R) can use several indicators to conclude that the pr…

  4. comment
    Comment #22294478

    Tor has made some improvements that would reduce the threat of deanonymizing an onion service, but none affect the above analysis (or rather, the above analysis has taken them into…

  5. comment
    Comment #22294008

    This is probably the best description of how Tor uses guards: https://gitweb.torproject.org/torspec.git/tree/guard-spec.tx... .

  6. comment
    Comment #22293873

    The page you link describes "vanguards" which apply the guard logic to positions beyond the first hop. They are only available as a plug-in that you must separately download and co…

  7. comment
    Comment #22293149

    In this case, the main question is how the server was discovered, not how the operator was then deanonymized. As the article describes, after the server was discovered to be in Fra…

  8. comment
    Comment #22292442

    Fair enough! I was using as a heuristic the expected number of compromised guards, which would be 0.02*50 = 1. Moreover, things degrade exponentially over time. If half the guards …

  9. comment
    Comment #22292161

    Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting s…

  10. comment
    Comment #18158533

    That's basically using a proxy, and so it has the same security. If the proxy is/geos bad (say, your VPS provider reveals your IP to some interested guys with guns), then you lose …

  11. comment
    Comment #18158455

    Thanks! The protection of the delay-based ballot-mixing looks somewhat weak. I see that the delay from one ballot batch to the next is set to a uniformly-random time between 10 and…

  12. comment
    Comment #18157784

    Honestly, I don't know why you need a blockchain in the first place. Just run your own accounting servers, which you already are doing for the Anonize ballots. It is certainly poss…

  13. comment
    Comment #18157508

    > Tech alone is never enough for anything like what we are doing. You'd be surprised how far you can get. For example, protocol design exist that provide strong message anonymity: …

  14. comment
    Comment #18157406

    Interesting, but decentralization does not equal privacy. Indeed, it might make privacy worse by sharing the data more widely and making it even easier to get copies of the data. C…

  15. comment
    Comment #18157314

    > Please read up on GDPR "purpose limitation". I am reasonably familiar with the contents of GDPR, having looked into it more after attending a lecture on the subject [0]. > We can…

  16. comment
  17. comment
    Comment #18157127

    An IP address is an identifier. If it weren't, there would be much less reason to use a VPN or Tor. Suppose I understand you correctly and you do see the network IPs and timestamps…

  18. comment
    Comment #18156634

    By the way, please do let me know if I'm wrong and Brave does provide good privacy while enabling payments. I have turned off Brave Payments because of the privacy issue, but I wou…

  19. comment
    Comment #18156593

    I understand that Anonize is used for anonymous ballots. I understand that Brave used to submit its ballots via a single-hop proxy. My understanding is now that Brave no longer use…

  20. comment
    Comment #18156502

    I support Brave's vision for the Web, but it currently seems to represent a step backwards for privacy. Making payments to providers essentially involves sending your Web browsing …

  21. comment
    Comment #16502382

    The problem seems well-advertised to me. From the Tor FAQ ( https://www.torproject.org/docs/faq.html.en#AttacksOnOnionRo... ): "it is possible for an observer who can view both you…

  22. comment
    Comment #14697266

    This is a pretty uncharitable comment. A nicer (and, in my opinion, more correct) take would be that their articles are written for people that enjoy reading and language. And the …

  23. comment
    Comment #11344705

    I'm not sure what you're arguing any more. Your argument started as that only Silk Road was a "notable" onion service, which you appeared to define as having "publicity". Then the …

  24. comment
    Comment #11344322

    My understanding is that Facebook runs an onion service (aka hidden service) primarily because it allows them to easily manage their anonymous users separately from other users. "M…

  25. comment
    Comment #10566238

    > I don't really buy the comparison that what CERT did is similar to a university-sponsored DDoS. I think a better parallel is the Dan Egerstad case. Here's why it's worse: they in…