Earlier quoted context omitted.
The traffic never leaves the Tor network. This has a few advantages: * You don't need a TLS certificate from a public certificate authority, as it is already encrypted end to end * The exit node cannot attempt to snoop on your traffic (via TLS SNI) or inject content/ads/exploits into your unencrypted traffic * It reduces load on the exit nodes so they can work on serving traffic to sites that don't have an .onion end…
If certificate authorities are a concern, then why do some onion services use https?
MoreOnionsPorfavor: Onionize your website and take back the internet
61–70 of 151 posts
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#62Earlier quoted context omitted.
A normal person won’t be able to access an onion site, let alone care about the pop up they’re getting about its availability. I’ve watched people navigate web pages with the half screen cookie banner still open. Tor is not targeting a “normal” person, as the media has already told the “normal” people that the only things available on the “dark”/“deep” web are illegal.
I'm one of those people that leave it open. I think I instinctively just avoid clicking on any pop up/over on a page. That being said, I am curious what happens if you don't click "accept" on those ones. I'm assuming you're implicitly accepting by not leaving?
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#63Earlier quoted context omitted.
Perhaps you are not familiar with Monero or Zcash.
I'm not familiar with many things. How does Monero or Zcash solve the problem of anonymity.
Monero makes it impossible to tell what is what and gives people who want to trace money a very hard time doing so.
ZCash uses Zero Knowledge Proofs. A ZK Proof (in this case zkSNARKs) is a way you can prove that you own a key to a second party without a third party being able to tell if there was an actual key involved (it is very easy for two colluding parties to fake a successfull ZK Proof).
IIRC ZCash basically allows you to prove that a transaction has moved money correctly between two accounts without revealing what accounts those are or how much money was transacted. There is knowlegde of how much money is in the shielded pool, ie, all money behind ZK Proofs.
Either approach has different advantages and disadvantages.
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#64Earlier quoted context omitted.
The traffic never leaves the Tor network. This has a few advantages: * You don't need a TLS certificate from a public certificate authority, as it is already encrypted end to end * The exit node cannot attempt to snoop on your traffic (via TLS SNI) or inject content/ads/exploits into your unencrypted traffic * It reduces load on the exit nodes so they can work on serving traffic to sites that don't have an .onion end…
If certificate authorities are a concern, then why do some onion services use https?
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#65I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…
> I would then refer them to law enforcement What kind of industry do you work in where the mere act of using Tor is reasonable suspicion of a law being broken?
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#66Earlier quoted context omitted.
I'm not familiar with many things. How does Monero or Zcash solve the problem of anonymity.
Monero uses ring-signatures; every transaction is signed by multiple signatures and it's impossible who is the actual signer. You also cannot tell what public address belongs to the signature, nor which public address is supposed to be the recipient. There is a reveal key that you can give tax authorities to reveal only you as a sender or receiver of a transaction but not the other end of it. Monero makes it impossib…
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#67CloudFlare had a much more elegant solution: the Alt-Svc HTTP header [1]. It is entirely transparent to the user. Security is guaranteed because it uses the original SSL/TLS certificate for exchange (that is, on top of the usual safety guarantees provided by a Tor hidden service). Sadly they stopped doing that a while ago [2]. If anyone has insider knowledge about the reason behind, I would be really interested to he…
Not a valid solution
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#68Earlier quoted context omitted.
I wasn't as active on the Internet during the initial rise of HTTPS, but I wonder how many companies, schools, and public stores threw the exact same fits back then when they realized there might be a world where they could no longer MITM every web request that went across their routers. I do remember the "kids who use Linux are hackers" arguments from schools; arguments that still occasionally pop up on rare occasio…
There is no legitimate use for it in this context, and as such, every single instance of it has been associated with a crime, mostly CSAM.
There's no legitimate usage for World of Warcraft on a work computer, and I'd happily ban that from work computers. But I also wouldn't hop onto an unrelated article for new players and imply that all of them were criminals. The linked article never mentions work computers, it's talking to website operators.
If your objection here is that you think Tor is inappropriate at this moment in one specific work setting, then fine, but that's not really adding anything to the conversation about whether or not general websites should be made available over Tor. It's just unrelated FUD.
I want to be clear, the goal of Tor proponents is for everyone to be running Tor (or something similar), and for most websites to be available over Tor by default. People should be running Tor on their smartphones, on their home laptops. Tor should be the default way that people share files with each other, and the default way that people set up technical blogs, or even just quick websites that show off pictures of their cat. The vision of the Tor project is a world where Tor is normal and ubiquitous for regular, non-technical people.
So unless your work policy bans all personal devices from your network, creating an expectation that any smartphone that joins and boots up a Tor browser automatically belongs to a criminal is contrary to the goals of the privacy movement. Our goal is that every device and every website should be private by default. Your network should be the exception, and it should only have company-owned devices on it.
And of course it's fine if you disagree with that, you don't have to be a privacy proponent. Lots of smart, reasonable people disagree with us about what the balance is between security and privacy. But demonizing Tor users in ordinary, everyday contexts is anti-Tor.
> or primarily available on onion routing, all workplaces will immediately block access and look at anyone who accesses with great incredulity
To go a step farther and suggest that making a website available over Tor should automatically mean that people who visit it are suspicious -- that is also anti-Tor and (I would argue) anti-privacy in general.
If I went into an interview for any company in any field offhandedly mentioning that I ran a Tor website, and then had to field a bunch of questions about whether or not I was a criminal, that would be a major red flag to me to avoid that company.
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#69Earlier quoted context omitted.
> I would then refer them to law enforcement What kind of industry do you work in where the mere act of using Tor is reasonable suspicion of a law being broken?
Financial services, but I suspect any business that provides hardware & software to it's employees would take the same view.
Re: MoreOnionsPorfavor: Onionize your website and take back the internet
#70Earlier quoted context omitted.
A normal person won’t be able to access an onion site, let alone care about the pop up they’re getting about its availability. I’ve watched people navigate web pages with the half screen cookie banner still open. Tor is not targeting a “normal” person, as the media has already told the “normal” people that the only things available on the “dark”/“deep” web are illegal.
I'm one of those people that leave it open. I think I instinctively just avoid clicking on any pop up/over on a page. That being said, I am curious what happens if you don't click "accept" on those ones. I'm assuming you're implicitly accepting by not leaving?
Reality is all over the place.