Live data from Hacker News

MoreOnionsPorfavor: Onionize your website and take back the internet

blog.torproject.org

41–50 of 151 posts

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#41

I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…

Naive question, as I am not a security professional. Why?

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#42

I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…

That seems like a bit of a knee-jerk reaction, you could just ask them not to use Tor on the company network. Some legit browser come bundled with it (Brave).

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#43

I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…

What logic is there behind what you wrote?

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#44
post #34

Earlier quoted context omitted.

"Web" definitely meant something to people as a metaphore, for long before the internet (ex. "web of lies"). "The 'internet' is like a spider's web, but each point in the web is a different computer." vs "Tor is like an onion, where each layer of the onion represents a computer acting like a relay, in a giant network of computers, which your traffic is routed through....."

There is a scene in Shrek where he compares himself to an onion because he was emotional layers.

Shrek is an old meme and onions are stinky. Do you think that's a recipe for this to catch on by the next generation? It's a miracle .com worked at all, and I wouldn't hold my breath for a second miracle.

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#45
post #41

I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…

Naive question, as I am not a security professional. Why?

In some businesses it is important that all employee communications are captured and can be inspected in case there is suspicion of IP or customer data theft.

For example in a hospital, there is no good reason for employee to use Tor on work computer.

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#46
post #38

CloudFlare had a much more elegant solution: the Alt-Svc HTTP header [1]. It is entirely transparent to the user. Security is guaranteed because it uses the original SSL/TLS certificate for exchange (that is, on top of the usual safety guarantees provided by a Tor hidden service). Sadly they stopped doing that a while ago [2]. If anyone has insider knowledge about the reason behind, I would be really interested to he…

Cloudflare is still using the Alt-Svc HTTP header. Use Ctrl+Shift+J to see the 'Browser Console' which contains logs in the form "Alternate Service Mapping found: https://blog.cloudflare.com:-1 to https://cflaresuje2rb7w2u3w43pn4luxdi6o7oatv6r2zrfb5xvsugj35....

Cloudflare only sends the header to clients it detects as Tor Browser. If you have tweaked your config or are running an older version, it may not detect correctly. Even if it had previously worked.

This technique is not "better than" the "Onion-Location" approach. They complement well. Use the 'Alt-Svc' header for all users with Tor Browser's user agent and send "Onion-Location" to all users. If a user decides to opt for the .onion address, they can. But they don't have to.

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#47

I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…

> I would then refer them to law enforcement

What kind of industry do you work in where the mere act of using Tor is reasonable suspicion of a law being broken?

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#48

I am tempted to onionize my site for political (if that is the correct word) reasons. I am almost done reading The Surveillance Economy and it feels like almost an obligation to push back. (Using ProtonMail, use a large leased server in Germany at Hetzner for my routine work and writing, and using private browsing tabs when I must use Twitter or Reddit.) It looks like Onion domain hosting services are $5-$8/month, bu…

you don't need to spend money if you have a server or even a raspberry pi or something—I run a mirror of my clearnet website as an onion service and it was a fairly straightforward setup.
Post reply on HN