The url is a bit hard to remember. https://www.nytimes3xbfgragh.onion/ Is there a directory of .onion sites? (with an easy .onion url)
I recall that Facebook brute forced their way into having an onion url that was easy to remember, by generating millions of them and then picking one that was simple.
The New York Times Is Now Available as a Tor Onion Service
81–90 of 205 posts
Re: The New York Times Is Now Available as a Tor Onion Service
#82Earlier quoted context omitted.
What does this mean in regular human terms?
I liked this post on EV certificates: https://www.troyhunt.com/on-the-perceived-value-ev-certs-cas...
Notably, Onion services tend to have URLs that are _very_ difficult for humans to remember (they're essentially just gibberish), and they're anonymous by default, meaning without an EV cert there's no easy way to check whether the service you're visiting is legitimate or not.
DV certs are also pretty useless for Onion services, since your connection is already encrypted and authenticated by Tor.
Re: The New York Times Is Now Available as a Tor Onion Service
#83Earlier quoted context omitted.
There exists a system that you wouldn't trust to provide a good-enough answer to the question "Does the onion service still serve the same advertisements their website and mobile app do?" ? What do you think an untrustworthy system is doing that would make it give a not-good-enough answer?
That's a clever question and the answer has a few parts, mostly due to the slipperiness of "trust" as a concept: I wasn't specific enough in my description of my own threat model (which makes sense, as my aim wasn't to explain the threat model but to cultivate answers from other folks). In short, I currently only have access to systems that are too costly to replace, if the site is under active attack. That's not to…
Re: The New York Times Is Now Available as a Tor Onion Service
#84Earlier quoted context omitted.
I guess I'm not everyone. I'd bet that the majority of the 'busts' are due to: a) Infiltrating chats where people are more likely to share sensitive information / trust the people they're talking to b) Poor configurations/ setups on either the client or server (client browser bundle has noscript, but it's not on the strictest settings, js is enabled iirc) c) Exploitation of client or server due to out of date version…
^ This. Remember, Silk Road was finally found and taken down because Ross Ulbrich messed up his OpSec on a Stack Overflow question.
Re: The New York Times Is Now Available as a Tor Onion Service
#85Earlier quoted context omitted.
Extended Validation certificate is when a company go to a CA and provide a bunch of business documents and legal proof that they really own the company behind a name. Its not a technical aspect but human lawyer human lawyer that establish a certificate. At the end if the validation is successful, the company get a technical signed document that in browsers shows up as a green lock and the name in green next to the UR…
> "a bunch of business documents and legal proof" In my case they just needed me to put an entry in the Yellow Pages...
Re: The New York Times Is Now Available as a Tor Onion Service
#86Earlier quoted context omitted.
Its not secure. "Everyone" knows that. Everytime a drug market is taken down or a pedophile ring is busted, the investigators from FBI always claim it was some dubious mistake from the admin whic lead to it. But we all know they have discovered a vulnurability in the TOR protocol but won't disclose it. Safe browsing guys //edit: if you want extra security. Launch TOR from a remote desktop. And I am not talking about…
> But we all know they have discovered a vulnurability in the TOR protocol but won't disclose it. Can you provide evidence for this claim? I'm a huge conspiracy nut, this has me excited.
That said, it's still the most reliable limited-anonymity provider I know of.
Re: The New York Times Is Now Available as a Tor Onion Service
#87Does the onion service still serve the same advertisements their website and mobile app do? If so, they're leaving their users-who-want-to-stay-relatively-anonymous open to attack via the advertisement vector. Members of that group would be considered high-value targets simply due to their anonymity desires. I can't see the number of daily users being large enough that they'd lose significant profit by closing that a…
I am curious about this as well. Tor is anonymous insofar as individual entrances and exits cannot be monitored. The advertising and other tracking pixels that would riddle something like the NYT site makes me think this is how some uncareful kingpin will fall, checking the op-eds.
Re: The New York Times Is Now Available as a Tor Onion Service
#88Earlier quoted context omitted.
Extended Validation certificate is when a company go to a CA and provide a bunch of business documents and legal proof that they really own the company behind a name. Its not a technical aspect but human lawyer human lawyer that establish a certificate. At the end if the validation is successful, the company get a technical signed document that in browsers shows up as a green lock and the name in green next to the UR…
> "a bunch of business documents and legal proof" In my case they just needed me to put an entry in the Yellow Pages...
Re: The New York Times Is Now Available as a Tor Onion Service
#89Earlier quoted context omitted.
That's a clever question and the answer has a few parts, mostly due to the slipperiness of "trust" as a concept: I wasn't specific enough in my description of my own threat model (which makes sense, as my aim wasn't to explain the threat model but to cultivate answers from other folks). In short, I currently only have access to systems that are too costly to replace, if the site is under active attack. That's not to…
Hey, Tom. I'll be right over with my laptop that I don't care about. You still on Green St.?
Re: The New York Times Is Now Available as a Tor Onion Service
#90So is it now "guaranteed", that TOR is secure? And how many "guarantees" does one need in order to be "guaranteed" security whilst browsing? [...]and they provide additional guarantees that readers are connected securely to our website.[...]
Its not secure. "Everyone" knows that. Everytime a drug market is taken down or a pedophile ring is busted, the investigators from FBI always claim it was some dubious mistake from the admin whic lead to it. But we all know they have discovered a vulnurability in the TOR protocol but won't disclose it. Safe browsing guys //edit: if you want extra security. Launch TOR from a remote desktop. And I am not talking about…