Live data from Hacker News

Italian Anti-Corruption Authority Adopts Onion Services

blog.torproject.org

51–60 of 101 posts

Re: Italian Anti-Corruption Authority Adopts Onion Services

#51

Earlier quoted context omitted.

This opinion is controversial, and I’m not going to go into all of the reasons why, but unless you REALY know what you’re doing Tor can’t be trusted. I’d wager only 1% of people on Hacker News would be capable of using a Tor setup for more than a day without getting owned. You’re better off buying a burner iPod or iPad, stick to public wifi spots, and factory reset it once a week. Even then, watch what you type since…

Even if you use it perfectly, between fingerprinting techniques which could be used to cross-reference your logged-in "normal" use and some of the communications Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched), I would be sure someone couldn't pierce the veil of anonymity.

> Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched)

That's an unfounded accusation. Micah Lee wrote a very concise refutation of his smear campaign.[1]

> I would be sure someone couldn't pierce the veil of anonymity.

That still doesn't contradict the fact that using Tor is better than not.

[1] : https://micahflee.com/2014/12/fact-checking-pandos-smears-ag...

Re: Italian Anti-Corruption Authority Adopts Onion Services

#52

Earlier quoted context omitted.

> Tor is far more fingerprintable than people think it is You seem to have no idea about the existence of pluggable transports.[1][2] > and its riddled with adversaries and malware. Yes, and so is I2P... Freenet... the Internet? > Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. Isn't that an argument for using Tor? As Mike Perry (who works now on the vanguard…

I've been on HN for almost 10 years. You aren't going to get a cut and dry answer from most pros because most pros aren't going to post things in public forums. Pluggable transports have nothing to do with it. I've actually helped defenders against Tor based attackers. I've de-anon'd them. It was easy as fucking shit because most attackers are dumb and the Tor browser isn't 0day proof or as network isolated as people…

> having a wipeable iPad will stop browser fingerprinting

Huh??

Re: Italian Anti-Corruption Authority Adopts Onion Services

#53
post #4

Nice. I am hoping onion services become more ubiquitous for desktop use. So many decentralized networks work so hard to solve things like NAT busting and network issues, and they still forget about anonymity. I am personally working on a tiny side project to build a chat/forum/etc platform based around onion services for all users. Traditionally, it was annoying to have to ask users to install Tor and open up the con…

A mix between IPFS and onions would also be very promising. There's current work on that.[1]

[1] : https://github.com/ipfs/notes/issues/37

Re: Italian Anti-Corruption Authority Adopts Onion Services

#54
post #4

Nice. I am hoping onion services become more ubiquitous for desktop use. So many decentralized networks work so hard to solve things like NAT busting and network issues, and they still forget about anonymity. I am personally working on a tiny side project to build a chat/forum/etc platform based around onion services for all users. Traditionally, it was annoying to have to ask users to install Tor and open up the con…

Would it be possible for you to port your work to I2P as well?

It's good to have a fallback network in case issues arise in Tor and something needs to plug the gap in the interim, and I2P would fulfill that roll pretty well.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#55

They're running a Tor website... that requires JavaScript. smh >Error! :( >Your browser is not running Javascript that is required to use the whistleblowing client. >It's common believe that Javascript and security don't sound well together, for this reason we suggest to use the Tor Browser, an extremely tuned FireFox browser with Tor integrated. Here you can found and download the latest release of: Tor Browser.

Note that those who want a JS-free whistleblowing platform should look for SecureDrop.[1] It's also harder to setup and may not be possible for certain threat models.

[1] : https://securedrop.org/directory

Re: Italian Anti-Corruption Authority Adopts Onion Services

#56

Earlier quoted context omitted.

To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it?

> To bolster your argument in a non-technical way: if Tor made users untrackable by US intelligence, would US intelligence really keep funding it? Maybe; if US intelligence's high-value targets can be targetted by means that Tor does not protect (compromising endpoints, emissions-based techniques, etc.), and Tor provides US intelligence agents a way to exfiltrate information in a way immune to any but more involved,…

Right, that's the theory, and certainly they do need users on Tor to create noise for their own agents. But considering their nonstop drive to weaken other forms of encryption and insert backdoors, I'd be a little bit cautious about taking that at face value if I wanted to start the next Silk Road.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#57
post #4

Nice. I am hoping onion services become more ubiquitous for desktop use. So many decentralized networks work so hard to solve things like NAT busting and network issues, and they still forget about anonymity. I am personally working on a tiny side project to build a chat/forum/etc platform based around onion services for all users. Traditionally, it was annoying to have to ask users to install Tor and open up the con…

A mix between IPFS and onions would also be very promising. There's current work on that.[1] [1] : https://github.com/ipfs/notes/issues/37

Yeah, I've seen that. OpenBazaar's onion transport is similar to what I'm talking about when I mean the user has to have their own tor process IIRC. I would have used Go instead of Rust of CGO on Windows and static compilation didn't suck so much.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#58

Earlier quoted context omitted.

Even if you use it perfectly, between fingerprinting techniques which could be used to cross-reference your logged-in "normal" use and some of the communications Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched), I would be sure someone couldn't pierce the veil of anonymity.

> Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched) That's an unfounded accusation. Micah Lee wrote a very concise refutation of his smear campaign.[1] > I would be sure someone couldn't pierce the veil of anonymity. That still doesn't contradict the fact that using Tor is better than not. [1] : https://micahflee.com/2014/12/fact-checking-pando…

That article is four years old. This claim I heard in an interview from him for his book that just came out (he got a bunch of e-mails through FOIA requests, as I understand it), and isn't addressed by this "very concise refutation." And some of the claims seem a little bit of a stretch (using the "Gate" suffix is a nod to Gamergate? Isn't it more plausible that this is the same reference to Watergate that's been applied to every political scandal since 1973?). And it seems like that article mostly agrees with all the factual claims it examines but disagrees with the interpretation or their level of significance, rather than exposing anything as a falsehood.

> That still doesn't contradict the fact that using Tor is better than not.

Is it a fact? If Tor achieves nothing for someone trying to hide from the government except announcing that you have something you want to hide (is that the case? I don't pretend to be certain, but it seems possible) then I'm not sure it's better.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#59
post #4

Nice. I am hoping onion services become more ubiquitous for desktop use. So many decentralized networks work so hard to solve things like NAT busting and network issues, and they still forget about anonymity. I am personally working on a tiny side project to build a chat/forum/etc platform based around onion services for all users. Traditionally, it was annoying to have to ask users to install Tor and open up the con…

Would it be possible for you to port your work to I2P as well? It's good to have a fallback network in case issues arise in Tor and something needs to plug the gap in the interim, and I2P would fulfill that roll pretty well.

There's not really much work to speak of yet. Last I looked at i2p, it carried a JVM with it and the C impl was not full featured iirc. Will have to look again.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#60
post #33
post #22

It's refreshing to notice that in the typical italian political climate of general incompetence, there are still people who do a good job.

You are right in the first part (I'm italian). Regarding people doing a good job, I don't know if this is the case. I tried to use this service (just to see how it works), and: - "anonymous reports will be considered only in particular cases" (!) - you cannot report if you are a private person/company - you have no kind of legal counseling / protection - other limitations I'm not sure if it was designed to get actual…

In fairness, some of that might just be inherent to the problem space; for instance, only considering anonymous reports in some cases could be a defense against random accusations with no actual evidence.
Post reply on HN