Live data from Hacker News

Tor Browser 9.5

blog.torproject.org

51–60 of 106 posts

Re: Tor Browser 9.5

#52
post #37

I downloaded the Tor Browser a decade ago, maybe even longer, in an effort to be privacy conscious. I used it here and there but I never made the switch to using Tor by default. Some time later I remember reading the US government was tracking people, or had a list of everyone, who had simply downloaded Tor. I also vaguely remember reading about how using Tor could potentially expose you to legal risks because of the…

If you're thinking about risks, it's important not to conflate 3 scenarios: (1) running a Tor exit node (potentially very risky), (2) running a Tor relay node, and (3) just using the Tor browser as a user (should probably be fine for most users - depends on what you use it for of course, and Tor by itself is of course not sufficient to solve all privacy issues - you can still be deanonymized if you're not careful).

Do you have any more information on how one could be deanonymized using Tor? I am aware of the browser fingerprinting and Tor themselves has a decent article about it but are there other methods that malicious parties could use?

https://blog.torproject.org/browser-fingerprinting-introduct...

Re: Tor Browser 9.5

#53
post #29

Earlier quoted context omitted.

This seems very risky. * Exit nodes might be run by malicious actors and unless you enforce always https they might snoop credentials. * If you login to platforms like google/facebook/twitter/stock overflow it might still be possible to track you. If you're worried that your employer is spying on you then tor can't help because they already have administrative access on your computer. I personally have a rule to neve…

Listen I'm not some Antifa here bombing the hell out of the next city over. I'm merely avoiding the botnet. How is it risky? What's the worst that could happen, I get tracked by the same people who would 100% track me without Tor Browser?

well, if you open non-HTTPS links you're trusting the exit node operator not not fuck with your data and to not snoop on it. So... don't do anything important without HTTPS. Same as always. As for the corporate spying... totally agree, worst case you didn't gain nor lose

Re: Tor Browser 9.5

#54

Earlier quoted context omitted.

The Tor Browser is scrutinized heavily. I know that is kind of a fallacious argument, but they have a routine presence at DefCon and they are really committed to protecting people around the world. At DefCon last year, the Tor project talked about the biggest security concern as countries who monitor the entry points to the network, and the challenges with getting those IPs distributed confidentially and keeping them…

> If you don't already know, Tor does require an entry IP address list before the anonymization occurs: countries can arrest people who visit these URLs, so this is the big challenge right now. Sorry, can you explain what this means? Would my home IP address be the "entry IP address" you're referring to?

No, it's the IP of the first relay.

Tor works pretty much like this:

You -> Relay 1 -> Relay 2 -> Relay 3 -> The website

Each arrow is an encrypted connection. The content of the exchange on a single arrow is the address of the next hop and the query of the next hop. Thanks to this:

- Relay 1 only knows you're going through Relay 2

- Relay 2 doesn't know who's asking (you) but knows it passed through Relay 1 and is going through Relay 3

- Relay 3 doesn't know who's asking (you) and where you entered, but knows it's going to the website

The nodes in the middle know everything that goes through them, but don't have the big picture.

The entry IP address is the IP address of Relay 1. Your computer must know an address to connect to, and that address is distributed in listings by the Tor Project. Since this listing is public, it also makes it easier for censors to censor, or at least detect who's interested in connecting through Tor

Re: Tor Browser 9.5

#55
post #37

Earlier quoted context omitted.

If you're thinking about risks, it's important not to conflate 3 scenarios: (1) running a Tor exit node (potentially very risky), (2) running a Tor relay node, and (3) just using the Tor browser as a user (should probably be fine for most users - depends on what you use it for of course, and Tor by itself is of course not sufficient to solve all privacy issues - you can still be deanonymized if you're not careful).

Do you have any more information on how one could be deanonymized using Tor? I am aware of the browser fingerprinting and Tor themselves has a decent article about it but are there other methods that malicious parties could use? https://blog.torproject.org/browser-fingerprinting-introduct...

Well a big one would be putting personally identifiable information on websites inside or outside the tor network.

Re: Tor Browser 9.5

#56
post #54

Earlier quoted context omitted.

> If you don't already know, Tor does require an entry IP address list before the anonymization occurs: countries can arrest people who visit these URLs, so this is the big challenge right now. Sorry, can you explain what this means? Would my home IP address be the "entry IP address" you're referring to?

No, it's the IP of the first relay. Tor works pretty much like this: You -> Relay 1 -> Relay 2 -> Relay 3 -> The website Each arrow is an encrypted connection. The content of the exchange on a single arrow is the address of the next hop and the query of the next hop. Thanks to this: - Relay 1 only knows you're going through Relay 2 - Relay 2 doesn't know who's asking (you) but knows it passed through Relay 1 and is g…

Do you know if GDPR prevents EU countries from obtaining IP logs for Amazon zones located there? I was hoping I could spin up an EC2 VPN in Europe and feel more secure that my IP logs can't be obtained by the US gov't. I use RunBox for email in Norway, which has the strictest privacy laws, but there is no AWS zone there. Any thoughts? Thanks.

Re: Tor Browser 9.5

#57

wait! the most privacy centric iOS doesn't support Tor?! but Android does! I wonder is privacy is just Apple's PR but far from truth. The speech to text translation also they need to route via their servers. The contractors listen to recordings of Siri. Its time to unmask Apple's true face.

Who cares if youre supporting Tor when the whole android platform is a mobile data collection trap. They own you on the device level.

Yeah you can root the 'droid and ditch the Goog Play Store, but you can jailbreak iOS.

Re: Tor Browser 9.5

#58
post #37

Earlier quoted context omitted.

If you're thinking about risks, it's important not to conflate 3 scenarios: (1) running a Tor exit node (potentially very risky), (2) running a Tor relay node, and (3) just using the Tor browser as a user (should probably be fine for most users - depends on what you use it for of course, and Tor by itself is of course not sufficient to solve all privacy issues - you can still be deanonymized if you're not careful).

Do you have any more information on how one could be deanonymized using Tor? I am aware of the browser fingerprinting and Tor themselves has a decent article about it but are there other methods that malicious parties could use? https://blog.torproject.org/browser-fingerprinting-introduct...

To use an obvious example, if you log into an account you've previously logged into directly from your home computer.

More broadly, any privacy tech can be undone by poor 'operational security'. For example Ross Ulbricht - 'Dread Pirate Roberts' of Silk road - posted on StackOverflow under his own name to ask "How can I connect to a Tor hidden service using curl in php?" [1]

[1] https://arstechnica.com/information-technology/2013/10/silk-...

Re: Tor Browser 9.5

#59
For what it's worth, Tor has been my default browser for the past 5 years to 'surf' the net and the experience is incomparable from 3 years ago to today, so much improvement specially on news sites with the 'Toggle reader view' or Reddit, Twitter, etc.

Give it a go if your experience wasn't great a few years back.

Re: Tor Browser 9.5

#60

I use Tor Browser for most of my day to day browsing to foil all the non-governmental corporate botnet spying. Of course I’m under no illusions that it secures you against the government. But I don’t do anything naughty so I’m not worried.

Sometimes I can't log into HN with Tor. Do you have that problem?

Yes, I do, and they also shadowban Tor accounts here, which is depressing.
Post reply on HN