Live data from Hacker News

MoreOnionsPorfavor: Onionize your website and take back the internet

blog.torproject.org

81–90 of 151 posts

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#81
post #62

Earlier quoted context omitted.

You can train uBlockOrigin to block them. A bit fiddly, and for every site, but that is my habit so I do not have to click 'accept'.

Or you can just use EasyList Cookie list.

Which isn't 100% perfect - I had it partially fail on several of the sites I visit leaving me with no way to view the sites, so disabled it.

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#82
post #41

Earlier quoted context omitted.

Naive question, as I am not a security professional. Why?

In some businesses it is important that all employee communications are captured and can be inspected in case there is suspicion of IP or customer data theft. For example in a hospital, there is no good reason for employee to use Tor on work computer.

> in a hospital, there is no good reason for employee to use Tor on work computer.

I would argue that hospitals and other public settings are actually more in need of higher privacy in electronic communications.

Imagine a physician working on, say, Scarlett Johansson's health issues; he periodically sends this data to the specialist that will run some test, and a creepy sysadmin finds out. Should he be able to MITM those comms, and resell the info to newspapers (or worse)...? Nope; the physician should have perfect privacy from network operators.

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#83

I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…

I wasn't as active on the Internet during the initial rise of HTTPS, but I wonder how many companies, schools, and public stores threw the exact same fits back then when they realized there might be a world where they could no longer MITM every web request that went across their routers. I do remember the "kids who use Linux are hackers" arguments from schools; arguments that still occasionally pop up on rare occasio…

> I wonder how many companies, schools, and public stores threw the exact same fits back then

Plenty did, but they were typically outgunned by the need for ecommerce transactions. Everyone had to order something with a credit card at some point.

TOR needs to find a mainstream killer-application like that, if it is to ever go beyond the current stereotypical demographic (hacktivists and criminals).

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#84

In this context OnionShare ( https://onionshare.org/ ) is an excellent program that even non-technical people can use to either share files or even complete static websites over Onion routing. The main advantage is you don't need to grub around with Nginx, Apache and the Tor daemon manually setting everything up.

OnionShare rocks: Tor hidden services are excellent for that purpose and provide a decentralized alternative for cloud based apps.

What I love about them is also that it works in in tricky NAT situations where WebRTC struggles.

My file manager "cryo" also uses Tor hidden services for signaling without a central server to initiate peer-to-peer connections. https://cryonet.io

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#85
post #7
post #2

I'm pro decentralizing the internet, but these movements really need some marketing chops. ".onion" TLD? (Yes I know it has been around for awhile) Think of how a normal person will view a ".onion" domain name. It's nonsensical to the uninitiated.

.tor would seem like it might make sense?

Are there other non-Tor onion routing programs? If so, .onion seems more generic and thus better. (I know that tor is the abbreviation of The Onion Router)

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#86

I'm in charge of a security for a reasonable sized company. I generally support the Tor project and the goals of having a surveillance free internet. However - if an employee would install tor browser or use tor on a company device, or a device attached to the company network, they would be fired immediately. I would then refer them to law enforcement after conducting a forensic audit. Should you make your site only…

I've been in charge of security in a company with a very popular product. Data leaks were a concern.

Yet, the Tor browser was recommended to protect employees from targeted attacks based on browser fingerprinting.

I'd like to hear what threat you are mitigating.

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#87
post #8
post #5

Earlier quoted context omitted.

What about http, ://, www and other TLDs like .co.nz or .ac.uk? All of these were pretty meaningless to initiates of the internet. In this new age of ".pizza" and suchlike, ".onion" doesn't seem much different or weird tbh. (To be clear: I don't think these new tlds are especially good either, but it's the world we live in now.)

To me, .onion reminds me too much of The Onion.

A common theme with country code tld's is that you get one country using someone else tld if and when there is a match in the local language and the two letters. For example, Sweden has a lot of swedish websites under the .nu (island state of Niue), to the point where the Swedish registrar actually bought and took over the operation of the tld. "nu" is the word for "now" in swedish.

For me who don't live in the states and have very little exposure of that satirical newspaper, .onion brings no connection to it. If I did not know about The Tor Project I would had guess it was a cooking related domain name. I would also have guessed that google was a company trying to sell glasses.

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#88
post #7

Earlier quoted context omitted.

.tor would seem like it might make sense?

Are there other non-Tor onion routing programs? If so, .onion seems more generic and thus better. (I know that tor is the abbreviation of The Onion Router)

There are (I2P being the main competitor), but .onion is entirely Tor-specific. I2P's equivalent of onion services use the .i2p "TLD".

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#89

Earlier quoted context omitted.

I am not an expert but as far as I understand it's harder to do correlation attacks when you're able to monitor network traffic when communication stays inside the Tor network. Additionally, you're replacing (or extending) CAs with Tor's public key cryptography for authentication and encryption. Computerphile did an interesting video series on this!

> replacing (or extending) CAs with Tor's public key cryptography Which is good because CAs are useless; they're complete overhead. Back when EV certificates meant something, they were marginally useful, but at this point, we might as well just switch to a TXT record that validates domain ownership. (Obviously, that doesn't protect against DNS MITM attacks, but that's a separate issue.)

Oh you mean storing some data to cryptographically verify that a particular server is associated with a domain? If I'm not mistaken, that's what .onion addresses are.

I wonder if anyone has tried putting .onion addresses into DNS and have clients treat them like address records...

Re: MoreOnionsPorfavor: Onionize your website and take back the internet

#90
I remember, in 2014, Facebook started to be available on Tor, and people speculated that there will be a wave of popular websites being offered on Torspace.

Nothing came of this "wave", if I'm not wrong, right.

https://en.wikipedia.org/wiki/Facebookcorewwwi.onion

edit: and it seems down to me right now.

edit2: it works... but slower, than just going to regual HTTPS version with Tor. Which makes sense, because it needs to hop more.

edit3: .... but it doesn't let me log in, as I am logging from "suspicious location".

Post reply on HN