Live data from Hacker News

The New York Times Is Now Available as a Tor Onion Service

open.nytimes.com

131–140 of 205 posts

Re: The New York Times Is Now Available as a Tor Onion Service

#131
post #10

And they're using an Extended Validation certificate from DigiCert for it CN = nytimes3xbfgragh.onion OU = Technology O = The New York Times Company Object Identifier (2 5 4 15) = Private Organization along with some other addresses DNS Name: nytimes3xbfgragh.onion DNS Name: graylady3jvrrxbe.onion DNS Name: *.graylady3jvrrxbe.onion DNS Name: *.dev.graylady3jvrrxbe.onion DNS Name: *.stg.graylady3jvrrxbe.onion DNS Name…

Sometimes I wonder if it's a good idea to brute-force these kinds of "vanity" onion prefixes. Take a look at the addresses used in http://incoherency.co.uk/blog/stories/hidden-service-phishin... ; they brute-forced the same prefix with a different suffix. Would anyone really notice?

Can you CNAME with onion domains? For example

onion.nytimes.com CNAME nytimes3xbfgragh.onion

Edit to clarify - more a technical pondering than a solution to anything

Re: The New York Times Is Now Available as a Tor Onion Service

#132

Earlier quoted context omitted.

I was asking because I'm currently nowhere near a system that I'd trust for this purpose. I'll be near one later and, if you're interested, I'll update the question with my findings.

There exists a system that you wouldn't trust to provide a good-enough answer to the question "Does the onion service still serve the same advertisements their website and mobile app do?" ? What do you think an untrustworthy system is doing that would make it give a not-good-enough answer?

I'm reading this from a bank workstation. Let me install Tor and see how long I can test NYTimes readability before I'm escorted out the door.

Re: The New York Times Is Now Available as a Tor Onion Service

#133

Earlier quoted context omitted.

Although there's a risk to using onion directories, since you have to trust that the hash they give you for the New York Times for example, is actually the real hash. It's easier to spoof onion hashes than domain names since domain names are more well known. You'd hopefully catch that you're connecting to nytim3s.com, not so much nytimes3xbfgra3h.onion.

EV certs can help with this to some extent. For example, the New York Times is using an EV cert with the organization name "The New York Times Company" for their hidden service. So as long as you trust the CA system, you can be certain that you're talking to a server operated by The New York Times, and not just a copycat.

Yes, but EV isn't that common on Tor. How would I distinguish Dread Pirate Roberts' Silk Road from FBI's Silk Road in a Tor online directory?

Re: The New York Times Is Now Available as a Tor Onion Service

#135
post #131

Earlier quoted context omitted.

Sometimes I wonder if it's a good idea to brute-force these kinds of "vanity" onion prefixes. Take a look at the addresses used in http://incoherency.co.uk/blog/stories/hidden-service-phishin... ; they brute-forced the same prefix with a different suffix. Would anyone really notice?

Can you CNAME with onion domains? For example onion.nytimes.com CNAME nytimes3xbfgragh.onion Edit to clarify - more a technical pondering than a solution to anything

.onion addresses aren't resolved using the DNS system. So... no?

I guess in theory a browser _could_ support something like that, but it'd be pretty unusual. I also think the idea of relying on DNS to resolve a hidden service would defeat a lot of the privacy and security guarantees associated with those services, so I don't think any browser serious about security would implement something like that.

Re: The New York Times Is Now Available as a Tor Onion Service

#136

Earlier quoted context omitted.

EV certs can help with this to some extent. For example, the New York Times is using an EV cert with the organization name "The New York Times Company" for their hidden service. So as long as you trust the CA system, you can be certain that you're talking to a server operated by The New York Times, and not just a copycat.

Yes, but EV isn't that common on Tor. How would I distinguish Dread Pirate Roberts' Silk Road from FBI's Silk Road in a Tor online directory?

Well, obviously EV is less useful [0] for services where the host’s anonymity is a key part of the reason the server is on Tor.

But for services on Tor that are fine with being identified but who wish there users to be opaque to third parties it seems to have some value.

[0] without a radically different CA infrastructure which has no chance of getting preloaded into browsers.

Re: The New York Times Is Now Available as a Tor Onion Service

#137

Earlier quoted context omitted.

TimesOpen is an engineer-driven blog. Its previous incarnation was self-hosted on a WordPress stack (separate from our main CMS), but for various reasons it was decided to re-platform. There were many discussions before settling on Medium and alternatives were considered (such as dogfooding our own CMS). We have a lot of work in-flight to modernize and simplify our publishing stack, and the timing wasn't right to rel…

How widely is WordPress being used at NYT today? Seems like it was used a lot about five years ago but don’t see it much anymore.

[deleted]

Re: The New York Times Is Now Available as a Tor Onion Service

#138
post #131

Earlier quoted context omitted.

Can you CNAME with onion domains? For example onion.nytimes.com CNAME nytimes3xbfgragh.onion Edit to clarify - more a technical pondering than a solution to anything

.onion addresses aren't resolved using the DNS system. So... no? I guess in theory a browser _could_ support something like that, but it'd be pretty unusual. I also think the idea of relying on DNS to resolve a hidden service would defeat a lot of the privacy and security guarantees associated with those services, so I don't think any browser serious about security would implement something like that.

Nice one cheers. I have no idea how .onion domains work, never used them/Tor

Re: The New York Times Is Now Available as a Tor Onion Service

#139
post #10

And they're using an Extended Validation certificate from DigiCert for it CN = nytimes3xbfgragh.onion OU = Technology O = The New York Times Company Object Identifier (2 5 4 15) = Private Organization along with some other addresses DNS Name: nytimes3xbfgragh.onion DNS Name: graylady3jvrrxbe.onion DNS Name: *.graylady3jvrrxbe.onion DNS Name: *.dev.graylady3jvrrxbe.onion DNS Name: *.stg.graylady3jvrrxbe.onion DNS Name…

Sometimes I wonder if it's a good idea to brute-force these kinds of "vanity" onion prefixes. Take a look at the addresses used in http://incoherency.co.uk/blog/stories/hidden-service-phishin... ; they brute-forced the same prefix with a different suffix. Would anyone really notice?

If you're that easily phished, why are you using TOR at all?

You aren't being attentive enough for high risk activities. You lack proper verification channels, to confirm authenticity, which matters in this context. You lack the situational awareness to proceed safely.

Admit that you might not be cut out for what it takes to maintain a secure posture on the internet, if that's what gets you. Just stop pretending to try.

Re: The New York Times Is Now Available as a Tor Onion Service

#140

Earlier quoted context omitted.

So in addition to knowing that your browser is connected to where you want, you now know that the website you want is actually who they say they are?

> you now know that the website you want is actually who they say they are? That's the idea. Of course, validation, while more thorough than for standard certs, still is not that reliable. My strong impression is that it could be fooled by anyone sufficiently motivated.

Not only that - in practice it's kind of meaningless, because if you were served a non-EV cert, you wouldn't notice. And there's usually other domains or subdomains that don't use the EV cert. It's mostly just a kind of token gesture by a business to claim they're more secure.
Post reply on HN