Live data from Hacker News

Tor's Fall Harvest: The Next Generation of Onion Services

blog.torproject.org

21–30 of 86 posts

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#21
post #15

Earlier quoted context omitted.

That's a valid point. Thanks for bringing that up. So now I have a private channel to that address and I don't have to worry about the exit nodes (unlike when I use Tor for clearnet sites). But now how do I know that I can trust the owner of that onion?

How do you know that you can trust the owner of any domain? How can you trust anyone? That's a deep philosophical question but doesn't really have anything to do with the technology you are using?

Reputation is a typical force in society. Businesses might want to do malicious things but the fear of destroying their identity helps to keep them in line.

Personally I trust something more when someone puts their reputation on the line for it.

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#22
post #19

Earlier quoted context omitted.

What would be the "correct onion address" for 3fyb44wdhnd2ghhl.onion?

That is the “correct onion address” for that hashcode, but you have to obtain the hashcode somehow.

And you might be obtaining a fake link from one of my phishing schemes that mimic the services you thought you were visiting...

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#23
post #19

Earlier quoted context omitted.

What would be the "correct onion address" for 3fyb44wdhnd2ghhl.onion?

That is the “correct onion address” for that hashcode, but you have to obtain the hashcode somehow.

Well, yes, obviously, in order to know something you have to know it!?

What I don't understand is what any of that has to do with any sort of "correctness"?!

How do you find out the correct name of James Miller? How do you find out the correct domain of google.com? That just seems like a set of nonsensical questions to me.

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#24
post #11

Earlier quoted context omitted.

Tor hides the identity of the service provider to third-party eavesdroppers . You might know someone and have gotten the onion address of a file upload server from them, but not want the government or your ISP to know who you're talking to. It also hides the a service provider's physical location (well, their IP address and hence location in the network graph) from even a user that knows their identity. You might kno…

To add to that, one useful application for hidden services is to enable SSH login on machines that are behind some impenetrable NATs/firewalls that you can't open up for inbound connections. Have a machine behind mobile, NAT only internet? Set up a tor hidden service and log in without any problems!

I use this in conjunction with Auth to use as low speed VPN to access home resources, and also for IRC gateway. No port fowarding configured!

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#25
post #21

Earlier quoted context omitted.

How do you know that you can trust the owner of any domain? How can you trust anyone? That's a deep philosophical question but doesn't really have anything to do with the technology you are using?

Reputation is a typical force in society. Businesses might want to do malicious things but the fear of destroying their identity helps to keep them in line. Personally I trust something more when someone puts their reputation on the line for it.

Well, yeah, sure ... so how would that be any different with tor hidden services?

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#26
post #11

Earlier quoted context omitted.

Tor hides the identity of the service provider to third-party eavesdroppers . You might know someone and have gotten the onion address of a file upload server from them, but not want the government or your ISP to know who you're talking to. It also hides the a service provider's physical location (well, their IP address and hence location in the network graph) from even a user that knows their identity. You might kno…

To add to that, one useful application for hidden services is to enable SSH login on machines that are behind some impenetrable NATs/firewalls that you can't open up for inbound connections. Have a machine behind mobile, NAT only internet? Set up a tor hidden service and log in without any problems!

I see this as a valid point. You don't need Tor for that, any local app could proxy a connection that way. But, yes, it is a useful side effect of Tor.

Re: Tor's Fall Harvest: The Next Generation of Onion Services

#30
post #26

Earlier quoted context omitted.

To add to that, one useful application for hidden services is to enable SSH login on machines that are behind some impenetrable NATs/firewalls that you can't open up for inbound connections. Have a machine behind mobile, NAT only internet? Set up a tor hidden service and log in without any problems!

I see this as a valid point. You don't need Tor for that, any local app could proxy a connection that way. But, yes, it is a useful side effect of Tor.

I mean, it's a free way to have a persistent internet address, which is interesting.

And in doing so you contribute to the usefulness of Tor, since it relies on people using it to create an anonymity set.

Post reply on HN