Live data from Hacker News

Tor Browser 9.5

blog.torproject.org

91–100 of 106 posts

Re: Tor Browser 9.5

#91
post #63

Anyone know what the HTML is for adding my onion address to my page for people visiting from the normal web entrance? I looked through the changelog for the bit about this auto-detection but didn't see it. Is it some sort of link tag thing in the like,

It's HTTP headers not HTML as far as I could tell. The article didn't say the exact name of the header but it mentions support.torproject.org uses it so looking into its headers: $ curl -I https://support.torproject.org/ [redacted] Onion-Location: http://4bflp2c4tnynnbes.onion/index.html [redacted]

Thanks! That was easy to implement.

Re: Tor Browser 9.5

#92

Earlier quoted context omitted.

The Tor Browser is scrutinized heavily. I know that is kind of a fallacious argument, but they have a routine presence at DefCon and they are really committed to protecting people around the world. At DefCon last year, the Tor project talked about the biggest security concern as countries who monitor the entry points to the network, and the challenges with getting those IPs distributed confidentially and keeping them…

> If you don't already know, Tor does require an entry IP address list before the anonymization occurs: countries can arrest people who visit these URLs, so this is the big challenge right now. Sorry, can you explain what this means? Would my home IP address be the "entry IP address" you're referring to?

[deleted]

Re: Tor Browser 9.5

#93

wait! the most privacy centric iOS doesn't support Tor?! but Android does! I wonder is privacy is just Apple's PR but far from truth. The speech to text translation also they need to route via their servers. The contractors listen to recordings of Siri. Its time to unmask Apple's true face.

Who cares if youre supporting Tor when the whole android platform is a mobile data collection trap. They own you on the device level. Yeah you can root the 'droid and ditch the Goog Play Store, but you can jailbreak iOS.

Jailbreaking is harder than rooting though and apple constantly fixes the holes so maintanence cost.

Few android manufacturers even have instructions to change your rom or root the phone. Lot of them support it while apple doesn't. Android is also open source so you can push your own changes at os level and reflash it . You can't do the same for iOS. You also have control over the hardware more than you do on iOS - way easily. Overclocking isn't possible on iphones.

Re: Tor Browser 9.5

#94

Earlier quoted context omitted.

Why do you think it fails as basic security against the government? Honestly curious. And what would you suggest instead. To my knowledge many dissidents and activists around the world are specifically using TOR because it supposedly does indeed provide protection against government tracking.

> Why do you think it fails as basic security against the government? Tor connections against normal sites use 3 hops while they use 6 hops against onion sites. Controlling or potentially even analysing the traffic from 2 of the hops is enough to know where the user connects to (it might be 4 hops for the onion case but I am not sure). I am pretty sure that NSA has enough resources for their own nodes. I2P has a bett…

You could've just said that you have a hunch.

Re: Tor Browser 9.5

#95

Earlier quoted context omitted.

Why do you think it fails as basic security against the government? Honestly curious. And what would you suggest instead. To my knowledge many dissidents and activists around the world are specifically using TOR because it supposedly does indeed provide protection against government tracking.

It’s literally funded and made by the NSA. Dissidents and activists have been busted using Tor and there’s always a friendly government damage control agent ready to pop up (any forum, any time of day) to remind people that Tor couldn’t possibly be backdoored or owned, it was always some other type of thing they used in parallel construction. Over-shilling is what clued next in. You don’t get this kind of response wi…

AES which is the encryption standard for asymmetric crypto and used everywhere (including by the gubment) was designed by the NSA. So what's your point?

Re: Tor Browser 9.5

#96
post #72

Earlier quoted context omitted.

On the topic of using Tor with a non-persistent OS, what I'd really like to see on that front is a federated encrypted bookmarking sync service integrated into the browser. Would be really neat if you could "sign-in" to the browser using a human-memorizable identifier to restore bookmarks and other settings. Obviously that opens up additional attack surface for de-anonymization attacks, but I think it could be done r…

Firefox Sync meets all the criteria you've described, except I don't think it has automatic Tor integration.

Firefox Sync is federated? I only ever saw an option to sync using my Firefox account. (Which is a non-starter for Tor; since my Firefox account is tied to my email address.)

I also didn't realize it was an open standard. Are there any other implementations besides the one in Firefox? I couldn't find any information on that.

Re: Tor Browser 9.5

#98

Earlier quoted context omitted.

> Why do you think it fails as basic security against the government? Tor connections against normal sites use 3 hops while they use 6 hops against onion sites. Controlling or potentially even analysing the traffic from 2 of the hops is enough to know where the user connects to (it might be 4 hops for the onion case but I am not sure). I am pretty sure that NSA has enough resources for their own nodes. I2P has a bett…

You could've just said that you have a hunch.

Are you kidding? What part of "Tor connections against normal sites use 3 hops while they use 6 hops against onion sites. Controlling or potentially even analysing the traffic from 2 of the hops is enough to know where the user connects to (it might be 4 hops for the onion case but I am not sure). I am pretty sure that NSA has enough resources for their own nodes" seems like a hunch?

Do you have something that you disagree with? If so just say it.

Re: Tor Browser 9.5

#99
post #35

brave browser has a "tor private window". such a great idea, since most people dont realize a private window is only private to their own browser. anyone know how updates to tor affect brave? it seems crucial it is kept to to date

updates to the tor library gets updated in brave most likely (if they care about its security) updates to the Tor Browser shouldn't affect it mostly unless they like a feature and they want to add it.

Re: Tor Browser 9.5

#100

Earlier quoted context omitted.

Sometimes I can't log into HN with Tor. Do you have that problem?

Yes, I do, and they also shadowban Tor accounts here, which is depressing.

Really? I don't think that's true: I use Tor (well, not right now, d'oh!) and people respond to my posts.
Post reply on HN