Will this help people in China at all? From an article I ready a while back it seemed like Tor has been defeated there. ( https://www.technologyreview.com/s/427413/how-china-blocks-t... )
That article is from 2012. It's a constant battle, which has changed a LOT in 5 years.
Tor Browser isolates cookies and other browser state into buckets based on URL bar domains.
... i.e. first party isolation, one can read more about it on the Tor Browser design document: https://www.torproject.org/projects/torbrowser/design/
How can I get first party isolation in regular chrome or firefox? That is exactly what I've been imagining/wanting since Firefox announced their new container prototype.
Extended Validation certificate is when a company go to a CA and provide a bunch of business documents and legal proof that they really own the company behind a name. Its not a technical aspect but human lawyer human lawyer that establish a certificate. At the end if the validation is successful, the company get a technical signed document that in browsers shows up as a green lock and the name in green next to the UR…
Why do we think a lawyer would be less likely to be duped? If they are relying on physical paper and pen signatures...aren't those all incredibly easy to fake?
And they're using an Extended Validation certificate from DigiCert for it CN = nytimes3xbfgragh.onion OU = Technology O = The New York Times Company Object Identifier (2 5 4 15) = Private Organization along with some other addresses DNS Name: nytimes3xbfgragh.onion DNS Name: graylady3jvrrxbe.onion DNS Name: *.graylady3jvrrxbe.onion DNS Name: *.dev.graylady3jvrrxbe.onion DNS Name: *.stg.graylady3jvrrxbe.onion DNS Name…
Sometimes I wonder if it's a good idea to brute-force these kinds of "vanity" onion prefixes. Take a look at the addresses used in http://incoherency.co.uk/blog/stories/hidden-service-phishin... ; they brute-forced the same prefix with a different suffix. Would anyone really notice?
If they didn't use vanity names, then people would only remember the first/last few random characters and the phishing scheme could very well still work, just it'd be less readable for visitors. I don't think we can assume that if all the characters were random they would remember them all better.
> hidden services I think you responded to your own question. Besides that there are lists of onion services. Apparently there are also search services like https://ahmia.fi/
Although there's a risk to using onion directories, since you have to trust that the hash they give you for the New York Times for example, is actually the real hash. It's easier to spoof onion hashes than domain names since domain names are more well known. You'd hopefully catch that you're connecting to nytim3s.com, not so much nytimes3xbfgra3h.onion.
EV certs can help with this to some extent. For example, the New York Times is using an EV cert with the organization name "The New York Times Company" for their hidden service. So as long as you trust the CA system, you can be certain that you're talking to a server operated by The New York Times, and not just a copycat.
... i.e. first party isolation, one can read more about it on the Tor Browser design document: https://www.torproject.org/projects/torbrowser/design/
How can I get first party isolation in regular chrome or firefox? That is exactly what I've been imagining/wanting since Firefox announced their new container prototype.
Will this help people in China at all? From an article I ready a while back it seemed like Tor has been defeated there. ( https://www.technologyreview.com/s/427413/how-china-blocks-t... )
Well there's meek-amazon[1] which seems to work there. Also I remember I talked last months to some guy on irc at #tor who was using some obfs4 bridges successfully in China. There's also another pluggable transport named Snowflake[2] where everyone can become a bridge by just running some JS in their browser, which may prove to be a good solution (it doesn't work yet in China since it uses Google for domain fronting).
I don't think he would disagree they are pro-establishment. He'd love them to be taken down though there is no way he could make this happen.
I think it's more that he'd prefer that the media didn't cite "unverified" dossiers that they sourced from Buzzfeed [0], which were produced by a source with ties to the DNC [1][2]. [0]: https://www.nytimes.com/2017/01/23/opinion/why-buzzfeed-news... [1]: https://www.nytimes.com/2017/01/11/us/politics/donald-trump-... [2]: http://www.washingtontimes.com/news/2017/oct/24/dnc-clinton-...
> I'd agree here. There's no reason to discuss politics on HN when there are numerous other places to do so.
HN is a forum about technology and the startup world, let's keep it about that.
I recall that Facebook brute forced their way into having an onion url that was easy to remember, by generating millions of them and then picking one that was simple.
That's clearly what the New York Times did as well (though probably with far less compute time than Facebook). nytimes3xbfgragh.onion is the easy to remember name they were able to generate.
Just say it out loud: En Why Times Three Ecks Bee Eff Gra{gargle}