Live data from Hacker News

Mozilla Project Fusion: Tor Integration into Firefox

trac.torproject.org

171–180 of 242 posts

Re: Mozilla Project Fusion: Tor Integration into Firefox

#171
post #105

Earlier quoted context omitted.

Where is the recommended place to run one?

https://trac.torproject.org/projects/tor/wiki/doc/GoodBadISP... (Also check the new relay guide: https://trac.torproject.org/projects/tor/wiki/TorRelayGuide )

Also get on the tor-relays@lists.torproject.org mail list.

But the sad truth is that there aren't that many hosting providers that allow Tor relays. Especially exit relays, because of abuse complaints.

Also, as you might expect, Tor relays can use lots of bandwidth. It's more common to get flat-rate bandwidth for 100 Mbps uplinks, and metered bandwidth for 1 Gbps uplinks. Digital Ocean, for example, just switched to metered bandwidth, and that has killed some relays.

However, all this could arguably change, if Tor became mainstream, as part of Firefox.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#172

Hi all. I am a Tor Project Developer and work at Mozilla on this project. We appreciate everyone's enthusiasm and feedback. Our ultimate goal is a long way away because of the amount of work to do and the necessity to match the safety of Tor Browser in Firefox when providing a Tor mode. There's no guarantee this will happen, but I hope it will and we will keep working towards it. If anyone is interested in assisting…

> first party isolate is generally more stable and usually only has breakage on particular login forms Are you referring to third-party login services and comment systems (such as disqus and similar)?

> Are you referring to third-party login services and comment systems (such as disqus and similar)?

See the full list of bugs of breakage when privacy.firstparty.isolate is enabled: https://wiki.mozilla.org/Security/FirstPartyIsolation#First_...

Re: Mozilla Project Fusion: Tor Integration into Firefox

#173
post #139

Earlier quoted context omitted.

Why take that trouble when they can do it directly using Tor without running any exit at home? Also for instance Bogatov had an alibi when that happened.

Most forums ban all Tor exits.

HN doesn't :)

Re: Mozilla Project Fusion: Tor Integration into Firefox

#174
post #126

Earlier quoted context omitted.

You already don't know what proxies your traffic is going through. Using Tor might increase the odds of a bad actor a bit but end-to-end security is something the web is getting better at right now.

The risk now is that some bad actor is replacing TLS certificates, which is an uncommon and tamper-evident event. Tor is handing your traffic to an unknown 3rd party. Plus, users do not understand what Tor is or how to use it. Fighting political battles with software is dumb — the end result is going to be a permanent loss of freedom, as governments force the use of platforms with trusted app stores.

The risk now is BGP hijacking. Or really just normal operation of BGP. You data could go anywhere on the planet on its way to the destination and you're not going to know ahead of time what path any particular packet will take.

If you're using TLS, it doesn't matter so much if the exit node is malicious because they still won't be able to read it.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#175

Earlier quoted context omitted.

The Fusion project is done by a subset of that team (+me, I happen to sit with Sandboxing due to other responsibilities).

By passing this on to Mozilla and discontinuing Tor Browser, you're going to inherit the innumerable issues in their code base. Wouldn't it be easier to hard-fork and create a simple browser with minimal overhead? It doesn't have to be loaded with features. Just minimalist and private. Some anti-features that come to my attention off the top of my head: * Biometric login (as of FF60) * Dumb PR Stunts like Mr. Robot *…

> By passing this on to Mozilla and discontinuing Tor Browser, you're going to inherit the innumerable issues in their code base.

What issues exactly? Tor Browser = Firefox ESR + some patches + some other stuff and tweaks. Before the release of the next ESR TB devs rebase and submit these patches to mainline Firefox, that's why you have prefs like privacy.resistFingerprinting and privacy.firstparty.isolate in mainline Firefox, see: https://wiki.mozilla.org/Security/Tor_Uplift

Re: Mozilla Project Fusion: Tor Integration into Firefox

#177
post #139

Earlier quoted context omitted.

Why take that trouble when they can do it directly using Tor without running any exit at home? Also for instance Bogatov had an alibi when that happened.

Most forums ban all Tor exits.

The forum I run only bans IP addresses caught posting link-spam. Which, admittedly, asymptotically approached 100% of Tor exit nodes before I instituted more rapid ban-expiration. I added faster ban-expiration after hearing from some of my privacy-conscious users that Tor had become unusable for my forum.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#178
Great news !

With wider adoption of ipv6 and all the good things that come with it (don't mistake me, they are great!) also comes the risk that each computer will get a uniquely identifiable IP address that will be used for fingerprinting. I've never really used Tor in the past, but this got me thinking about it.

An option could be to provide a webRTC-based node, but I am not sure how feasible that would be, after reading some comments here. Maybe for entry nodes and guard nodes instead of exit nodes? The transient nature of browser sessions could greatly enhance privacy. Of course, you would need some algorithms to deal with this very nature... But I can imagine some.

This surely lowers the barrier to entry for greatly enhanced privacy. Quite a lot of people seem to be aware of the private browsing mode, and I can imagine this being turned into a simple toggle on the private browsing home page, along with a short explanation (and a link to additional privacy tips).

A low hanging fruit that could enhance the privacy a bit would be to use the trusted recursive resolver (DNS over https) in private browsing by default, since it already is part of Firefox. It just needs a default trusted resolver.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#179
post #70

Earlier quoted context omitted.

Which sites in 2018 still present multiple CAPTCHAs to users with cookies and JavaScript enabled? I think the theory behind this project is that those problems are primarily caused by Tor's popular image as a 'fringe network for pedophiles and drug dealers' and that by making it more mainstream they can fix those issues. (please more replies saying "that sounds really hard" and less replies saying "tor is not a fring…

Cloudflare.

It's OK now, they no longer show a captcha on most websites behind Cloudflare.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#180

Earlier quoted context omitted.

The Fusion project is done by a subset of that team (+me, I happen to sit with Sandboxing due to other responsibilities).

By passing this on to Mozilla and discontinuing Tor Browser, you're going to inherit the innumerable issues in their code base. Wouldn't it be easier to hard-fork and create a simple browser with minimal overhead? It doesn't have to be loaded with features. Just minimalist and private. Some anti-features that come to my attention off the top of my head: * Biometric login (as of FF60) * Dumb PR Stunts like Mr. Robot *…

Tor Browser will exist as long as Tor feels it needs to. If the features or anti-features in FF cause them to believe Firefox does not fit their need, then we're/they're not going to discontinue it.
Post reply on HN