Live data from Hacker News

Italian Anti-Corruption Authority Adopts Onion Services

blog.torproject.org

91–100 of 101 posts

Re: Italian Anti-Corruption Authority Adopts Onion Services

#91

Earlier quoted context omitted.

> You're in league with wannabe terrorists, misguided natsec journalists, blackhats, child pornographers. Stop this FUD. You can make the same argument about safes, VPNs, disk encryption, paper, roads, etc. etc. ad nauseam. What are the specific exploits in Tor which are “easy as shit” to use? If you’re unable to be specific, why is that?

> safes, VPNs, disk encryption, paper, roads except you can't since the ratios are totally different.

Of course you can. This is the argument used by governments in the UK and other countries, e.g. for key disclosure law (it’s illegal to possess encrypted data which you are unable to decrypt upon demand).

Even 5 - 10 years ago, basic disk encryption was seen as pretty sophisticated, in a “what’s at risk if you’re willing to do that?” kind of way. Now it’s standard. You can say similar things for 50 char randomized passwords encrypted on the client, TPMs, TLS by default, etc. etc.

The ratios are likely to change over time as more people realize that their privacy is important.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#92
post #83

The more one studys the mechanics of corruption, the more one begins to understand that a similar battle has been waged in biology since the dawn of time. The corrupting entity can not replace the corrupted entity, because it does not have the sufficient structures- and would fall prey to other corrupting entitys almost instantly. It can not grow bigger then the corrupted entity, due to its being dependent regarding…

I would love to read this as a much longer article with links. What did you mean with the fox?

My father is a hunter- he observed foxes, with lots of fleas ripping out hair and then going slowly into ponds, letting the raft of hair float away with the fleas on them.

I have to admit i never observed this myself, so for what is worth is currently hear say.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#93

Earlier quoted context omitted.

> safes, VPNs, disk encryption, paper, roads except you can't since the ratios are totally different.

Of course you can. This is the argument used by governments in the UK and other countries, e.g. for key disclosure law (it’s illegal to possess encrypted data which you are unable to decrypt upon demand). Even 5 - 10 years ago, basic disk encryption was seen as pretty sophisticated, in a “what’s at risk if you’re willing to do that?” kind of way. Now it’s standard. You can say similar things for 50 char randomized pa…

But that's an "in the future" argument. now you get put on watchlists - because the ratios for early adopters are different.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#94
post #89

Earlier quoted context omitted.

> and suggest an up to date OpSec guide to using Tor? Use Disposable Whonix VMs in Qubes OS (available in the 4.0-rc4) for the best secure experience that you can get right now. For less security, an alternative would be to use Tails or Subgraph. You can also control how much attack surface you expose in your browser in the Security Settings in the Tor Button (Medium (now termed Safe) disables JS on HTTP websites, JI…

In what way are Disposable Whonix VMs in Qubes OS more secure than Tails? I understand that the VM won't have access to the real IP address, but isn't there a possibility of breaking through the VM (while with Tails the entire system is disposable)? Are there other ways that it is more secure?

> In what way are Disposable Whonix VMs in Qubes OS more secure than Tails?

To de-anonymize Tails one needs to exploit Tor Browser first, then get root access. For Disposable Whonix VMs in Qubes OS one would need the additional availability of a Xen exploit to break out of the VM in order to de-anonymize it.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#95

Earlier quoted context omitted.

I haven't really had time to go through everything, so I was just going by what I remembered from the interview. The idea that they were sharing zero-days seemed like a big deal but I didn't really see which one he was referring to skimming those earlier, so I didn't bother linking. The other point he harped on a lot was them taking marching orders (for instance, that the application should be localized for Farsi dur…

The zero-day claim is repeated here. https://twitter.com/yashalevine/status/960889610841837569

Can he give a legitimate source for that very serious claim? Note how he overplays a lot of things that are publicly and openly known. Yes, the Tor Project got funding at various points in time from the state department to improve "human rights" and "freedom of speech" around the world, especially certain countries deemed hostile to the US. So what? Yes, Roger Dingledine publicly stated (in a CCC talk) that he gave a talk at the NSA and another one at the GCHQ. So what? Does that mean that he's suddenly an NSA shill that will try to implement a backdoor in Tor for the simple reason that he gave a talk to them?

If the Internet is such a surveillance threat, and Tor doesn't help, why doesn't this Yasha Levine point to a single alternative?

Edit: Went through this https://twitter.com/itdaniher/status/961307347950940161 It seems he's just a FUD spreader and not someone interested in actual solutions.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#96

Earlier quoted context omitted.

> Yasha Levine dug up (showing that Tor gave intelligence services early notice of vulnerabilities that had not been patched) That's an unfounded accusation. Micah Lee wrote a very concise refutation of his smear campaign.[1] > I would be sure someone couldn't pierce the veil of anonymity. That still doesn't contradict the fact that using Tor is better than not. [1] : https://micahflee.com/2014/12/fact-checking-pando…

That article is four years old. This claim I heard in an interview from him for his book that just came out (he got a bunch of e-mails through FOIA requests, as I understand it), and isn't addressed by this "very concise refutation." And some of the claims seem a little bit of a stretch (using the "Gate" suffix is a nod to Gamergate? Isn't it more plausible that this is the same reference to Watergate that's been app…

> That article is four years old.

So? It was just an example to show how Mr. Yasha misrepresents and twists facts to fit his preconceived conspiracy theory.

> Is it a fact?

Yes, because of the three hops design.

> If Tor achieves nothing for someone trying to hide from the government except announcing that you have something you want to hide (is that the case?

Millions of people use Tor nowadays that the mere fact that you connected directly to the Tor network doesn't reveal much. Not to mention that there are ways to hide the fact that you're using Tor thanks to pluggable transports.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#97

Earlier quoted context omitted.

The zero-day claim is repeated here. https://twitter.com/yashalevine/status/960889610841837569

Can he give a legitimate source for that very serious claim? Note how he overplays a lot of things that are publicly and openly known. Yes, the Tor Project got funding at various points in time from the state department to improve "human rights" and "freedom of speech" around the world, especially certain countries deemed hostile to the US. So what? Yes, Roger Dingledine publicly stated (in a CCC talk) that he gave a…

Well, I'd guess the footnote represented a source, so I am thinking it is in the book.

As for "actual solutions," what do you have in mind? His claim is that it's a political problem and that throwing tech at the problem won't solve it.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#98

Earlier quoted context omitted.

That article is four years old. This claim I heard in an interview from him for his book that just came out (he got a bunch of e-mails through FOIA requests, as I understand it), and isn't addressed by this "very concise refutation." And some of the claims seem a little bit of a stretch (using the "Gate" suffix is a nod to Gamergate? Isn't it more plausible that this is the same reference to Watergate that's been app…

> That article is four years old. So? It was just an example to show how Mr. Yasha misrepresents and twists facts to fit his preconceived conspiracy theory. > Is it a fact? Yes, because of the three hops design. > If Tor achieves nothing for someone trying to hide from the government except announcing that you have something you want to hide (is that the case? Millions of people use Tor nowadays that the mere fact th…

As I said, I don't see anything in that article that makes me think that "Mr. Yasha" twisted any facts; simply that the author of the article doesn't agree with his interpretation.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#99
post #89

Earlier quoted context omitted.

In what way are Disposable Whonix VMs in Qubes OS more secure than Tails? I understand that the VM won't have access to the real IP address, but isn't there a possibility of breaking through the VM (while with Tails the entire system is disposable)? Are there other ways that it is more secure?

> In what way are Disposable Whonix VMs in Qubes OS more secure than Tails? To de-anonymize Tails one needs to exploit Tor Browser first, then get root access. For Disposable Whonix VMs in Qubes OS one would need the additional availability of a Xen exploit to break out of the VM in order to de-anonymize it.

Thank you for the straightforward explanation.

Re: Italian Anti-Corruption Authority Adopts Onion Services

#100

Earlier quoted context omitted.

Can he give a legitimate source for that very serious claim? Note how he overplays a lot of things that are publicly and openly known. Yes, the Tor Project got funding at various points in time from the state department to improve "human rights" and "freedom of speech" around the world, especially certain countries deemed hostile to the US. So what? Yes, Roger Dingledine publicly stated (in a CCC talk) that he gave a…

Well, I'd guess the footnote represented a source, so I am thinking it is in the book. As for "actual solutions," what do you have in mind? His claim is that it's a political problem and that throwing tech at the problem won't solve it.

He's just a FUD spreader, as demonstrated on the other posts, so just move on. If you think Tor isn't a technical solution then please provide alternatives.
Post reply on HN