Live data from Hacker News

Mozilla Project Fusion: Tor Integration into Firefox

trac.torproject.org

131–140 of 242 posts

Re: Mozilla Project Fusion: Tor Integration into Firefox

#131

Earlier quoted context omitted.

Google has always been showing captchas when using their search engine for quiet a long time (even for VPN users). In fact they were even straight blocking users from using that very same captcha: https://bugs.torproject.org/23840

I more meant that Google offers a captcha service for others that is quite good, them implemented a really terrible one for the internal services. It truly is awful to deal with. Whoever made it must have been smoking crack or taking large quantities of lsd

> I more meant that Google offers a captcha service for others that is quite good, them implemented a really terrible one for the internal services.

They're identical now, I rarely got the awful one that you're talking about when searching on Google.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#132

Earlier quoted context omitted.

You also get encryption while your traffic looks just the same as everybody else’s. You don’t stand out like when you’re using Tor.

> You also get encryption while your traffic looks just the same as everybody else’s. You don’t stand out like when you’re using Tor. Detecting WhatsApp usage is trivial. With Tor you can use pluggable transports to obfuscate your traffic.

But everyone and their cousin is a WhatsApp user, so using Whatsapp isn't suspicious.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#133
post #115
post #61

Earlier quoted context omitted.

I'm trying to get that rule changed and working with several other organizations on this.

Are there public discussions somewhere yet? I always find it interesting to peek into these processes.

We talked about it in this thread in November.

https://cabforum.org/pipermail/public/2017-November/thread.h...

Since then Fotis Loukos and I have drafted a ballot, which I believe he plans to introduce soon after asking a few other organizations to look it over.

You can subscribe to the cabfpub mailing list without becoming an Interested Party or Member. Only Interested Parties or Members can post to the list, while only Members can introduce or vote on ballots.

(Edit: Strangely, the reason for this is seemingly not that they're worried that the general public will make crazy suggestions, but rather that the general public will make patented suggestions, without being willing to license them according to the Forum's patent policy, and thereby sneak patented technology into the standards.)

Re: Mozilla Project Fusion: Tor Integration into Firefox

#134

Earlier quoted context omitted.

I can't read this article because I'm at work, but unless they managed to solve the problem of Tor being very, very, very slow, this will never happen. End users will definitely notice a difference and likely won't care about their privacy. They'll just see Firefox being way slower than Chrome and switch.

Tor is not that slow these days. Sometimes you get a bad circuit but you can reroute and expect speeds comparable to mobile phone networks.

Yes it is. I can't speak for everyone, but in Brazil, it's virtually impossible to use Tor even for HTML-only websites. And I can say most people have a slower bandwidth than I.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#135
post #56

Earlier quoted context omitted.

Those standards have nothing to do with Tor's speed.

Not immediately, but I feel that as those protocols become more ubiquitous, _maybe_ the base Tor transport protocol (for nodes which aren't bridges) might be able to benefit from some of the same upgrades by using them? I don't know how much (if at all) it might help—but other, similar overlay networks have previously noticed that (intuitively) inefficiency in the transport protocol is likely to be (broadly speaking)…

There are in fact some vague ideas floating around about using QUIC as a transport protocol for Tor. However, there is so much work to do and so few people that have the necessary skills (solid cryptography -- not at a "build the next AES" level, but "implement AES with no side channels" is already incredibly difficult -- plus low-level networking, C, and so on...) that in my view it is a minimum of 2-3 years from being mainstream available (look at how long HSv3 took).

Re: Mozilla Project Fusion: Tor Integration into Firefox

#136

Cool, now let me start an ephemeral v3 onion service from JS and have it reachable via WebRTC by a peer who has their own. It's the perfect tech marriage, removes signalling servers and NAT busters, but may be a bit taxing on directory servers and too slow to use for media streams (but I'll take data channels only).

sounds really useful, but to be fair, it doesn't really remove either. you're effectively just using the Tor network as freely available (but slow) signalling and TURN servers.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#137

Hi all. I am a Tor Project Developer and work at Mozilla on this project. We appreciate everyone's enthusiasm and feedback. Our ultimate goal is a long way away because of the amount of work to do and the necessity to match the safety of Tor Browser in Firefox when providing a Tor mode. There's no guarantee this will happen, but I hope it will and we will keep working towards it. If anyone is interested in assisting…

Thanks for your effort! If I can ask, how much overlap exists between your team and the team overseeing the implementation of security protocols within Firefox e.g. HSTS, CSP, etc.? It'd be neat to see Firefox drive innovation here alongside the effort to weave Tor into the browser; although I wouldn't necessarily treat Tor integration the same as I might the implementation of other security specifications, I can see…

The Fusion project is done by a subset of that team (+me, I happen to sit with Sandboxing due to other responsibilities).

Re: Mozilla Project Fusion: Tor Integration into Firefox

#138

Earlier quoted context omitted.

Is it a fork? I thought it was a heavily customized version of Firefox ESR with specific settings and defaults using the channels OEM configs. Looking at the binaries, it's definitely not the standard build anymore.

OEM configs have never been enough to implement everything they need in Tor Browser. They eventually started their uplift effort [1], to upstream all the patches and features they've added to it, so that they can possibly just use OEM configs. Project Fusion is a superset of that effort. [1] https://wiki.mozilla.org/Security/Tor_Uplift

Could someone please explain what "OEM configs" means here?

Re: Mozilla Project Fusion: Tor Integration into Firefox

#139
post #102

Earlier quoted context omitted.

Looks like a cheap escape from jail card. Run an exit node and then do something illegal. Then blame it on someone else.

Why take that trouble when they can do it directly using Tor without running any exit at home? Also for instance Bogatov had an alibi when that happened.

Most forums ban all Tor exits.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#140
post #102

Earlier quoted context omitted.

Looks like a cheap escape from jail card. Run an exit node and then do something illegal. Then blame it on someone else.

Did you miss the part where exit node operators are getting arrested?

They sometimes are. Not always. And they walk out free, except for that Jewish guy who lived in Austria (I can’t remember his name but he was the only one to get in real trouble for running an exit node).
Post reply on HN