Live data from Hacker News

BBC News launches 'dark web' Tor mirror

bbc.co.uk

261–270 of 306 posts

Re: BBC News launches 'dark web' Tor mirror

#261
post #239

Earlier quoted context omitted.

you can download the brave.com browser for desktop, which supports Tor. After creating a Tor tab I could view https://www.bbcnewsv2vjtpsuy.onion/ without issue

You should not use Brave Browser to access .onion websites. It makes you easier to target and identify and you stand out. Tor Browser has millions of active daily users VS Brave Browser has only a very small amount.

Sometimes that's okay. Sometimes you don't care about privacy and just want to use a network system where people actually own their domain names instead of lease them on the whim of a corporation.

Re: BBC News launches 'dark web' Tor mirror

#262

Some of BBC News' .onion neighbors are forced to constantly rotate their URLs to evade DDoS attacks (notably Empire Market). Admins constantly publish new PGP-signed links to https://dark.fail . DDoS attackers then scrape this site, shift their attacks. Sites stay online, but users are trained to expect URLs to constantly change. This has resulted in a huge spike in phishing attacks. Tor hidden services are notorious…

My pet theory is that these DDOS attacks are not just other merchants. I believe state actors are DDOSing to force traffic through nodes they control to deanonymize traffic.

Re: BBC News launches 'dark web' Tor mirror

#263

BTW NYtimes has been doing this for a while. https://open.nytimes.com/https-open-nytimes-com-the-new-york... https://www.nytimes3xbfgragh.onion/

Lulz, what good is a paywalled tor site? Does NYT accept crypto, or do you have to get throwaway plastic to pay them pseudonymously?

Is it paywalled? Maybe your exit node was used to scrape? I don't read NYT much but when I've checked out the .onion such as today I've had no issue reading articles.

Re: BBC News launches 'dark web' Tor mirror

#264

Many of you with homelabs ought to check out how to run a Tor relay or bridge. It's been fun setting mine up, and after a while I started getting lots of traffic! No data cap on a symmetric fiber connection, so I might as well share the love!

This is different from an exit node, right?

Don’t worry. You won’t get a subpoena or get a surprise visit from you-know-what. Tor relays just relays data, while exit nodes relay data from tor to Internet.

Re: BBC News launches 'dark web' Tor mirror

#265
post #259

Earlier quoted context omitted.

That page talks about malicious relays in the sense that they spoil traffic either through incompetence or malfeasance. What I am thinking about is the hypothetical case that 3000 of the 6000 active relays today had been started and operated by Eve over the last few years according to Tor guidelines and without any external sign that the nodes were centrally controlled. If that were true it would be hard for a user t…

You’re not misunderstanding Tor. Indeed, if you control more than 50% of the nodes then you can feasibly deanonymize clients. Tor circuits tend to go through many countries and rarely do they go through the same country twice. Not sure if this is part of the node selection criteria. But if you can’t have two nodes within a circuit go through the same country, and someone identifies you, then you’re dealing with a hel…

> But if you can’t have two nodes within a circuit go through the same country, and someone identifies you, then you’re dealing with a hell of a global adversary.

You can do that with a credit card and AWS. Setting up server presence in multiple countries is trivial. Setting up enough of them is expensive.

Re: BBC News launches 'dark web' Tor mirror

#268

I know there are good reasons why it's not fully secure, but I'd really like to be able to access `.onion` addresses in my regular browser over TOR and everything else directly as usual. In _this_ I'm not over-worried about the risk of deanonymisation as my aim is on one hand access to resources I don't have access to now and on the other hand legitimisation of TOR as something that anyone could reasonably use, even…

You can use a browser extension such as foxyproxy to specify proxy settings based on url patterns. Just tell it to use the SOCKS proxy of the Tor daemon for .onion addresses, and the I2P proxy for .i2p adresses for example.

Re: BBC News launches 'dark web' Tor mirror

#269
post #115

Earlier quoted context omitted.

You absolutely should use Tor for regular non-logged in browsing if you can bear the slowness. Exit bandwidth is limited, but I'd say being a needle in the haystack of people who actually need the privacy is a net benefit. I'd just really advise against touching Tor with a regular browser. For starters, you shouldn't browse Tor without blocking JavaScript by default. Hogging the bandwidth needed for video is also whe…

Seems like you are being the haystack instead of the needle in this case.

Well, that or he is a rare strand of hay in a stack made mostly of needles.

(I'm stretching the analogy to point out that you are correct that he is providing cover [the hay], but that most of the traffic currently is of the type that the surveilling entity is looking for [the needles]).

Re: BBC News launches 'dark web' Tor mirror

#270
post #259

Earlier quoted context omitted.

That page talks about malicious relays in the sense that they spoil traffic either through incompetence or malfeasance. What I am thinking about is the hypothetical case that 3000 of the 6000 active relays today had been started and operated by Eve over the last few years according to Tor guidelines and without any external sign that the nodes were centrally controlled. If that were true it would be hard for a user t…

You’re not misunderstanding Tor. Indeed, if you control more than 50% of the nodes then you can feasibly deanonymize clients. Tor circuits tend to go through many countries and rarely do they go through the same country twice. Not sure if this is part of the node selection criteria. But if you can’t have two nodes within a circuit go through the same country, and someone identifies you, then you’re dealing with a hel…

Sure, but if the CIA, NSA, FBI, UK, China, and Russia are all trying to control nodes, they keep each other from getting a useful share of the nodes. There are many parties that would want to deanonymize the traffic.
Post reply on HN