Live data from Hacker News

Italian Anti-Corruption Authority Adopts Onion Services

blog.torproject.org

81–90 of 101 posts

Re: Italian Anti-Corruption Authority Adopts Onion Services

#81
post #33
post #22

It's refreshing to notice that in the typical italian political climate of general incompetence, there are still people who do a good job.

You are right in the first part (I'm italian). Regarding people doing a good job, I don't know if this is the case. I tried to use this service (just to see how it works), and: - "anonymous reports will be considered only in particular cases" (!) - you cannot report if you are a private person/company - you have no kind of legal counseling / protection - other limitations I'm not sure if it was designed to get actual…

Also - fellow Italian here - I guess we must apologize for the English grammar/syntax in:

>Error! :(

>Your browser is not running Javascript that is required to use the whistleblowing client.

>It's common believe that Javascript and security don't sound well together, for this reason we suggest to use the Tor Browser, an extremely tuned FireFox browser with Tor integrated. Here you can found and download the latest release of: Tor Browser.

This said, the issue revolves more generally about the Italian Law, anonymous reports have much lesser credit/relevance than signed ones (this is understandable).

Besides the internet/modern way, the concept of "esposto anonimo" (anonymous report ) is well planted in the Law, but has very low "relevance", basically if you send one you are just suggesting the Authority to look in a certain direction, but there is no guarantee whatever that they will do so.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#82
The more one studys the mechanics of corruption, the more one begins to understand that a similar battle has been waged in biology since the dawn of time.

The corrupting entity can not replace the corrupted entity, because it does not have the sufficient structures- and would fall prey to other corrupting entitys almost instantly. It can not grow bigger then the corrupted entity, due to its being dependent regarding nourishment on the corrupted entity.

All is fair in this little war. Strategys include shedding hard to corrupt matter (skin, muscus, nails and hair), have tissue with incredible replacement rates (colon-cells). Fast pace the life cycle of the corrupted entity, and have not enough nourishment in the offspring to continue the corruption.

Remedys include using of all natural substances (eat leaves to kill the worms), to behaviour changes (famous the way foxes bath, with a brush of hair forming a flea-raft)

Synchronize breeding cycles, to starve parasites and diseases. Destroy breeding grounds and switch locations, for stationary parasites.

Diversify into different corrupted entity-types to prevent specialized parasites from target hopping.

Im aware that this is dangerous comparison, and thus want to press that i do not compare humans with vermin. I do compare organizations made up by humans with organisms and parasites.

This measure is basically encouraging the parasites infrastructure to turn upon themselves. There is no reward and there is no protection of the parasite being damaged. So it will be used mainly by other parasites to battle among one another (leak information about the neighboring clan)- or to have parasites on the parasites (aka the lower echelon members of the mafia removing upper echelons to raise).

Re: Italian Anti-Corruption Authority Adopts Onion Services

#83

The more one studys the mechanics of corruption, the more one begins to understand that a similar battle has been waged in biology since the dawn of time. The corrupting entity can not replace the corrupted entity, because it does not have the sufficient structures- and would fall prey to other corrupting entitys almost instantly. It can not grow bigger then the corrupted entity, due to its being dependent regarding…

I would love to read this as a much longer article with links. What did you mean with the fox?

Re: Italian Anti-Corruption Authority Adopts Onion Services

#84
post #77

Stupid question: there are so many public places that provide free wifi without authentication. If you go into one of these places and it is populated enough, and you have MAC randomization on, no smartphone on you, isn’t it good enough? Surely there are CCTV. But if you connect from a changing room or toilets of a busy mall, I don’t see how anyone could trace the connection.

At the very least you need to add a VM into that mix to stop (most of) the fingerprinting. You also need a trusted VPN, all kinds of JS and privacy blockers.

And that's assuming there are no hidden backdoors in your hardware. Which will be used, if you're important enough to track.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#85
post #77

Stupid question: there are so many public places that provide free wifi without authentication. If you go into one of these places and it is populated enough, and you have MAC randomization on, no smartphone on you, isn’t it good enough? Surely there are CCTV. But if you connect from a changing room or toilets of a busy mall, I don’t see how anyone could trace the connection.

At the very least you need to add a VM into that mix to stop (most of) the fingerprinting. You also need a trusted VPN, all kinds of JS and privacy blockers. And that's assuming there are no hidden backdoors in your hardware. Which will be used, if you're important enough to track.

But Tor won't protect you against hardware backdoors either. If you disable javascript and open an incognito chrome session, I don't think browser fingerprinting can do much harm. If all you are doing is submitting a form on a whistle blower hotline, I'd expect it to be reasonably secure.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#86
post #75

Earlier quoted context omitted.

> having a wipeable iPad will stop browser fingerprinting Huh??

The theory is that making your computer less finger printable and hence less unique is near impossible compared to a iPad you wipe on every use (you still have to use the iPad for other things). https://panopticlick.eff.org/ is pretty scary I'm almost always unique unless I do a trick like that.

An iPAd or any mobile device, including Android or Windows Mobile ones, runs mostly off closed software and drivers. You can wipe it completely but if the network device firmware instructs it to send a small magic packet somewhere to tell which terminal is that and where to find it, you're lost. If it had eavesdropping malware on it, it will be installed back with the next upgrade. Unless one can set up packet inspection and filtering on a mobile network, and manufacturers release everything (hardware+firmware+software) as open source, there's no way to have security on any mobile device, including those sold as super secure. This sadly also applies to bench PCs too, although the choice of the OS to install and being able to implement filtering lessens the problem just a bit.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#87

Earlier quoted context omitted.

If you're good enough to understand how to use Tor securely you're good enough to know why random "newbuser"s shouldn't be on it. Tor is far more fingerprintable than people think it is and its riddled with adversaries and malware. Even if you're good you have a separate problem now: Keeping the USG et al from painting a target on you. It isn't worth it. You're in league with wannabe terrorists, misguided natsec jour…

> You're in league with wannabe terrorists, misguided natsec journalists, blackhats, child pornographers. Stop this FUD. You can make the same argument about safes, VPNs, disk encryption, paper, roads, etc. etc. ad nauseam. What are the specific exploits in Tor which are “easy as shit” to use? If you’re unable to be specific, why is that?

> safes, VPNs, disk encryption, paper, roads

except you can't since the ratios are totally different.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#88

Earlier quoted context omitted.

He posted the FOIAd docs here: https://surveillancevalley.com/the-tor-files/master-list He and I discussed them a bit on Twitter: https://twitter.com/itdaniher/status/961307347950940161 I was not impressed by his response. The "bunch of emails" seemed remarkably banal. I've written similar emails about sponsored open-source work myself. edit: email stack 1: https://www.documentcloud.org/documents/4367176-Tor-BBG-corr…

I haven't really had time to go through everything, so I was just going by what I remembered from the interview. The idea that they were sharing zero-days seemed like a big deal but I didn't really see which one he was referring to skimming those earlier, so I didn't bother linking. The other point he harped on a lot was them taking marching orders (for instance, that the application should be localized for Farsi dur…

The zero-day claim is repeated here. https://twitter.com/yashalevine/status/960889610841837569

Re: Italian Anti-Corruption Authority Adopts Onion Services

#89
post #2

Anyone able to comment on the state of Tor security and suggest an up to date OpSec guide to using Tor?

> and suggest an up to date OpSec guide to using Tor? Use Disposable Whonix VMs in Qubes OS (available in the 4.0-rc4) for the best secure experience that you can get right now. For less security, an alternative would be to use Tails or Subgraph. You can also control how much attack surface you expose in your browser in the Security Settings in the Tor Button (Medium (now termed Safe) disables JS on HTTP websites, JI…

In what way are Disposable Whonix VMs in Qubes OS more secure than Tails? I understand that the VM won't have access to the real IP address, but isn't there a possibility of breaking through the VM (while with Tails the entire system is disposable)? Are there other ways that it is more secure?

Re: Italian Anti-Corruption Authority Adopts Onion Services

#90
post #85

Earlier quoted context omitted.

At the very least you need to add a VM into that mix to stop (most of) the fingerprinting. You also need a trusted VPN, all kinds of JS and privacy blockers. And that's assuming there are no hidden backdoors in your hardware. Which will be used, if you're important enough to track.

But Tor won't protect you against hardware backdoors either. If you disable javascript and open an incognito chrome session, I don't think browser fingerprinting can do much harm. If all you are doing is submitting a form on a whistle blower hotline, I'd expect it to be reasonably secure.

> If you disable javascript and open an incognito chrome session, I don't think browser fingerprinting can do much harm.

Try it. I'm pretty sure you will end up unique:

https://amiunique.org

Post reply on HN