Live data from Hacker News

Mozilla Project Fusion: Tor Integration into Firefox

trac.torproject.org

221–230 of 242 posts

Re: Mozilla Project Fusion: Tor Integration into Firefox

#221

Earlier quoted context omitted.

The Fusion project is done by a subset of that team (+me, I happen to sit with Sandboxing due to other responsibilities).

By passing this on to Mozilla and discontinuing Tor Browser, you're going to inherit the innumerable issues in their code base. Wouldn't it be easier to hard-fork and create a simple browser with minimal overhead? It doesn't have to be loaded with features. Just minimalist and private. Some anti-features that come to my attention off the top of my head: * Biometric login (as of FF60) * Dumb PR Stunts like Mr. Robot *…

>Biometric login (as of FF60)

Are you talking about Web Authentication? What is wrong with it?

Re: Mozilla Project Fusion: Tor Integration into Firefox

#222
post #169

So we lose another valuable project of the Web. I wonder why I feel so lost - that when I was young, the Internet was barely born... and now I'm watching it die.

What's going to be lost?

Tor Browser. A single privacy-dedicated browser package; even if it is now being built on Chromefox.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#223
post #130

Okay but what about maidsafe, dat, ipfs etc. The correct solution is to have firefox expose a 'protocol api' or something along those lines so that any 'alternate internet' project can create a backend extension to make firefox compatible with that protocol.

Seems like some people are working precisely on that. See for instance: https://blog.mozilla.org/addons/2018/01/26/extensions-firefo... (CTRL-F Decentralization) https://github.com/mozilla/libdweb

That's amazing to see. Thanks for sharing.

This is exactly the kind of tech Mozilla should be supporting - tech that gives users more freedom on the internet.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#224

Hi all. I am a Tor Project Developer and work at Mozilla on this project. We appreciate everyone's enthusiasm and feedback. Our ultimate goal is a long way away because of the amount of work to do and the necessity to match the safety of Tor Browser in Firefox when providing a Tor mode. There's no guarantee this will happen, but I hope it will and we will keep working towards it. If anyone is interested in assisting…

Seconding the other posters who mentioned that tor relays and Tor exit nodes are two very different things.

"Why you need balls of steel to run a Tor exit node":

https://lists.torproject.org/pipermail/tor-talk/2009-Septemb...

Given the low level of technical knowledge with a great deal of US law enforcement, increasing militarization, no knock warrants, etc... Please think twice before running an exit node from your house. Do it in Colo somewhere with a small, plucky ISP owned by a first and fourth amendment absolutist.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#225
post #145

Hi all. I am a Tor Project Developer and work at Mozilla on this project. We appreciate everyone's enthusiasm and feedback. Our ultimate goal is a long way away because of the amount of work to do and the necessity to match the safety of Tor Browser in Firefox when providing a Tor mode. There's no guarantee this will happen, but I hope it will and we will keep working towards it. If anyone is interested in assisting…

> You can also run Tor relays and help us improve the health of the network by working with Tor's new Relay Advocate Since I've seen this come up before in many previous discussions of Tor I think it's worth emphasizing/clarifying up front: Tor relays are not the same as Tor exit nodes. Relays do not talk to the public internet, they serve only the full encrypted internal Tor virtual network. So they won't ever send…

And plenty of people insist that Tor relays are totally safe to run. They are not. I NEVER ran an exit node from my home IP, only relays, and my IP was still blacklisted from various sites due to this behavior.

I still contribute to Tor via VPS rentals and such, but relays are not no-risk alternatives to exit nodes. Period.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#226
post #145

Earlier quoted context omitted.

> You can also run Tor relays and help us improve the health of the network by working with Tor's new Relay Advocate Since I've seen this come up before in many previous discussions of Tor I think it's worth emphasizing/clarifying up front: Tor relays are not the same as Tor exit nodes. Relays do not talk to the public internet, they serve only the full encrypted internal Tor virtual network. So they won't ever send…

And plenty of people insist that Tor relays are totally safe to run. They are not. I NEVER ran an exit node from my home IP, only relays, and my IP was still blacklisted from various sites due to this behavior. I still contribute to Tor via VPS rentals and such, but relays are not no-risk alternatives to exit nodes. Period.

This is also, sadly, why the individual V4 /24 netblock of cheap VPS providers have terrible IP space reputations in most aggregated abuse systems.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#227

I believe Tor browser is already just a version of Firefox if I'm not mistaken. What would be the advantage of integrating with Firefox as opposed to say, a VPN integrated into the browser via a plugin. Just seems a little redundant and Tor is beginning to seem dated also with new solutions popping up and making the pitfalls of Tor more apparent.

The vpn owner knows all traffic flowing through it.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#228

Earlier quoted context omitted.

The Fusion project is done by a subset of that team (+me, I happen to sit with Sandboxing due to other responsibilities).

By passing this on to Mozilla and discontinuing Tor Browser, you're going to inherit the innumerable issues in their code base. Wouldn't it be easier to hard-fork and create a simple browser with minimal overhead? It doesn't have to be loaded with features. Just minimalist and private. Some anti-features that come to my attention off the top of my head: * Biometric login (as of FF60) * Dumb PR Stunts like Mr. Robot *…

> Google Chrome (large contract Mozilla has with them as they backport this into IPC)

What's this?

Re: Mozilla Project Fusion: Tor Integration into Firefox

#229
post #145

Earlier quoted context omitted.

> You can also run Tor relays and help us improve the health of the network by working with Tor's new Relay Advocate Since I've seen this come up before in many previous discussions of Tor I think it's worth emphasizing/clarifying up front: Tor relays are not the same as Tor exit nodes. Relays do not talk to the public internet, they serve only the full encrypted internal Tor virtual network. So they won't ever send…

And plenty of people insist that Tor relays are totally safe to run. They are not. I NEVER ran an exit node from my home IP, only relays, and my IP was still blacklisted from various sites due to this behavior. I still contribute to Tor via VPS rentals and such, but relays are not no-risk alternatives to exit nodes. Period.

Do you have any idea why it's unsafe? In theory, public site should even be able to see your IP. How would they blacklist you?

Edit: nvm, found the answer by pricechild below.

Re: Mozilla Project Fusion: Tor Integration into Firefox

#230

Earlier quoted context omitted.

Please.

Here, I pulled my docs for ya: https://gist.github.com/jleclanche/91f2f5c0f2042a81db1c61464... They basically created their own git protocol + virtual filesystem, optimized for asset patches inside large compressed binary files. I wish they'd open source it.

That was interesting to poke through.

Related discussion: https://news.ycombinator.com/item?id=13140257

Post reply on HN