Viewing profile — ohmygodel
ohmygodel
HN member- Joined
- Mon, Sep 20, 2010, 2:05 AM UTC
- HN karma
- 340
- Public activity
- 52 items
- HN profile
- View on Hacker News ↗
About ohmygodel
No profile information was provided.
Recent public activity
-
comment
Comment #22297737
Yes, if you manually and wisely choose your own guard nodes, then you can avoid these attacks. You should be sure that those guards can't themselves be linked to you, either.
-
comment
Comment #22295649
I assume you refer to [0]. He says "If [the adversary] can knock me off enough guards, my tor daemon will eventually choose one of his guards. Then he can identify my actual networ…
-
comment
Comment #22294946
The Tor protocol doesn't explicitly signal the guard relay that it is in the guard position. However, the guard relay (call it R) can use several indicators to conclude that the pr…
-
comment
Comment #22294478
Tor has made some improvements that would reduce the threat of deanonymizing an onion service, but none affect the above analysis (or rather, the above analysis has taken them into…
-
comment
Comment #22294008
This is probably the best description of how Tor uses guards: https://gitweb.torproject.org/torspec.git/tree/guard-spec.tx... .
-
comment
Comment #22293873
The page you link describes "vanguards" which apply the guard logic to positions beyond the first hop. They are only available as a plug-in that you must separately download and co…
-
comment
Comment #22293149
In this case, the main question is how the server was discovered, not how the operator was then deanonymized. As the article describes, after the server was discovered to be in Fra…
-
comment
Comment #22292442
Fair enough! I was using as a heuristic the expected number of compromised guards, which would be 0.02*50 = 1. Moreover, things degrade exponentially over time. If half the guards …
-
comment
Comment #22292161
Running a hosting server for onion services, as was done in this case, is a terrible idea. It greatly increases the risk of deanonymization. The question is less how this hosting s…
-
comment
Comment #18158533
That's basically using a proxy, and so it has the same security. If the proxy is/geos bad (say, your VPS provider reveals your IP to some interested guys with guns), then you lose …
-
comment
Comment #18158455
Thanks! The protection of the delay-based ballot-mixing looks somewhat weak. I see that the delay from one ballot batch to the next is set to a uniformly-random time between 10 and…
-
comment
Comment #18157784
Honestly, I don't know why you need a blockchain in the first place. Just run your own accounting servers, which you already are doing for the Anonize ballots. It is certainly poss…
-
comment
Comment #18157508
> Tech alone is never enough for anything like what we are doing. You'd be surprised how far you can get. For example, protocol design exist that provide strong message anonymity: …
-
comment
Comment #18157406
Interesting, but decentralization does not equal privacy. Indeed, it might make privacy worse by sharing the data more widely and making it even easier to get copies of the data. C…
-
comment
Comment #18157314
> Please read up on GDPR "purpose limitation". I am reasonably familiar with the contents of GDPR, having looked into it more after attending a lecture on the subject [0]. > We can…
- comment
-
comment
Comment #18157127
An IP address is an identifier. If it weren't, there would be much less reason to use a VPN or Tor. Suppose I understand you correctly and you do see the network IPs and timestamps…
-
comment
Comment #18156634
By the way, please do let me know if I'm wrong and Brave does provide good privacy while enabling payments. I have turned off Brave Payments because of the privacy issue, but I wou…
-
comment
Comment #18156593
I understand that Anonize is used for anonymous ballots. I understand that Brave used to submit its ballots via a single-hop proxy. My understanding is now that Brave no longer use…
-
comment
Comment #18156502
I support Brave's vision for the Web, but it currently seems to represent a step backwards for privacy. Making payments to providers essentially involves sending your Web browsing …
-
comment
Comment #16502382
The problem seems well-advertised to me. From the Tor FAQ ( https://www.torproject.org/docs/faq.html.en#AttacksOnOnionRo... ): "it is possible for an observer who can view both you…
-
comment
Comment #14697266
This is a pretty uncharitable comment. A nicer (and, in my opinion, more correct) take would be that their articles are written for people that enjoy reading and language. And the …
-
comment
Comment #11344705
I'm not sure what you're arguing any more. Your argument started as that only Silk Road was a "notable" onion service, which you appeared to define as having "publicity". Then the …
-
comment
Comment #11344322
My understanding is that Facebook runs an onion service (aka hidden service) primarily because it allows them to easily manage their anonymous users separately from other users. "M…
-
comment
Comment #10566238
> I don't really buy the comparison that what CERT did is similar to a university-sponsored DDoS. I think a better parallel is the Dan Egerstad case. Here's why it's worse: they in…