Live data from Hacker News

The German Problem with Tor

worldofmatthew.com

91–100 of 131 posts

Re: The German Problem with Tor

#91

Recommending to host an exit node in Switzerland in the context of TOR feels like reading an article of someone who thinks they are anonymous by using TOR. Switzerland is even more privacy invasive than German laws, and that is the case since 2010 when automated connection tagging was introduced for VND and VÜPF.

>Switzerland is even more privacy invasive than German laws

Why even more? Germany also do's connection tagging, and additionally always thinks about to hold the transported data too (vorratsdatenspeicherung). The problem described here is that the possibility to have a entrance node and a exit node in Germany is really high, because Germany is the biggest provider in tor bandwidth.

Re: The German Problem with Tor

#92
post #27

Earlier quoted context omitted.

I wasn't aware of that :( Which country would be best in your opinion? It seems it's becoming quite hard to find one that doesn't do this now.

There are none. Full stop. Anyone who thinks otherwise is just delusional.

Tzzzz, look up sealand ;)

Re: The German Problem with Tor

#93

Recommending to host an exit node in Switzerland in the context of TOR feels like reading an article of someone who thinks they are anonymous by using TOR. Switzerland is even more privacy invasive than German laws, and that is the case since 2010 when automated connection tagging was introduced for VND and VÜPF.

I wasn't aware of that :( Which country would be best in your opinion? It seems it's becoming quite hard to find one that doesn't do this now.

Iceland is the best country for free information (leaks etc), Romania the best for potential copyrighted stuff (torrent etc)

Re: The German Problem with Tor

#94
post #73
post #51

Earlier quoted context omitted.

There are no shades of grey here - state actors have access to every internet node, fibre optic cables, operating systems and hardware. So unless you take your time to build your own CPU, main board and modem and only use our own private direct fibre connection, you're a potential target for being spied on. It's as simple as that. You can make things harder by encrypting your traffic, but that's possible regardless o…

You say "There are no shades of grey here" but then you contradict it by saying "You can make things harder by encrypting your traffic", so obviously you don't mean it. By dismissing the imperfect possiblities of making yourself safer, you seem to be saying "there only needs to be one gunner to shoot you when you look out the window, so either you never leave your bunker or may as well live in a war zone", while dism…

There is no place in the world that is both technologically capable of reliably hosting servers and at the same time inherently safer with regards to the privacy of your data than others.

If it's not the domestic government that will raid the server or monitor traffic, it's foreign actors or (in case of monitoring) the country that packets are routed through.

Yes, there are possibilities to make yourself safer, but they don't depend on where you place your data.

The question wasn't "can I be safer", the question was "is there a specific place that is safer" and the answer is no, for the reasons I gave.

That's not saying "encryption is useless anyway" or "you might as well give up" - no! I'm saying that if the privacy of your data depends on where your server is located, then you're doing it wrong.

Re: The German Problem with Tor

#95

Earlier quoted context omitted.

> A company on the other hand, would have no issues fleecing people and abusing their power for profit if they only could. Governments often abuse their power. They have absolutely no problem with that either. It's precisely because they do this that total population surveillance should be impossible rather than a standard government tool. Abuse of surveillance powers could manifest in any number of ways. For example…

> Governments often abuse their power. They have absolutely no problem with that either. The way I think about it is this. Governments and companies are both organizations made up of people. Governments have additional powers (for instance, military force, police power, etc.) over companies. The checks and balances for gov't abuse of power depend on the type i.e. representative democracy, republic, etc. And the check…

The difference is often referred to as 'voice vs. exit'. You have a 'voice' (your say/vote) with the government, but no right to 'exit'. In contrast, with a private party, you only have a right not to transact with them (exit), but no right to tell them what to do (voice).

Your desired scope of government usually reflects how much you believe in exit and voice. For practical purposes, this usually translates to how efficient you think competition is, and how effective you think democracy is.

https://en.wikipedia.org/wiki/Exit,_Voice,_and_Loyalty

Re: The German Problem with Tor

#96
post #51

Earlier quoted context omitted.

There are no shades of grey here - state actors have access to every internet node, fibre optic cables, operating systems and hardware. So unless you take your time to build your own CPU, main board and modem and only use our own private direct fibre connection, you're a potential target for being spied on. It's as simple as that. You can make things harder by encrypting your traffic, but that's possible regardless o…

You contradict yourself. If there are no shades of gray, why don't you post a link here to a website with cameras into your home, a direct link to a microphone you carry at all times, passwords to all your accounts and the public "View" link to a dropbox with all you data. Because you know... Since there is no 100% privacy and safety, there is just none. So why even bother?

That's not at all what I'm saying. What I'm saying is that privacy and security don't depend on where your data is located.

The location of your server or whether third parties have access to that server one way or another should not be part of your security concept.

My point is that if you have end-to-end encryption and don't store or share unencrypted data in the first place, it doesn't matter where your server is.

There is no particular country in the world where you can place your Tor relay or your storage server and be safe against being spied on.

To use the obligatory car allegory since it's Germany we're talking about: an unlocked car with the keys in the ignition isn't any safer against theft if you park it next to a police station. On the other hand you can park a locked car with a live pitbull inside (in the shade!) pretty much anywhere in town and the risk of theft will be equally low.

Re: The German Problem with Tor

#97
post #78

Earlier quoted context omitted.

I can see where you're coming from but this analogy does not hold up. The German Constitutional Court (GCC) does exercise its powers, but it tries not to break anything, therefore it gives the responsible actors some time to change the law/their behavior. Maybe another example: The Court decided that the (specific calculation of the) German property tax was unconstitutional. But if they just declared the whole tax vo…

You originally posted a response to this. > Rulings of the constitutional court have almost no real life consequences. If there is a negative ruling the parliament is given ample time before the unconstitutional law must be replaced. If there is any replacement within that time, the same law, formulated differently, is passed. To say that the court does have power. But your example is an example of exactly what the O…

Yes you are correct, that is an example except for this part

>If there is any replacement within that time, the same law, formulated differently, is passed

Which is not accurate. Actually the new laws are substantially different, in the case of the ground tax this is also very obvious.

Re: The German Problem with Tor

#98
post #4

"In reality, the German government has a double standard when it comes to the right to privacy. They will fully support that right if it's company's violating your privacy (especially, if they are American because protectionism) but in contrast, the German will give itself as many powers as it can to spy on its own citizens and those abroad." This.

That's only double standards if one considers states and companies as being in the same position. A state and a company have vastly different goals. A state should care for its citizens, this includes protections against threats to public safety (terror, organized crime) and surveillance is a tool in the box for that. A company on the other hand, would have no issues fleecing people and abusing their power for profit…

A state has coercive power over you, a company doesn't.

From my point of view, the government can do (and does) 100 more damage to me than any single company could do.

A company can sell my personal data if I'm not careful. The state can send me to jail for saying things they don't like or doing things they don't like, even when those things don't do any harm to other people (e.g. using LSD). The state also steals a big portion of people's money, usually for no good reason.

Re: The German Problem with Tor

#99
post #4

"In reality, the German government has a double standard when it comes to the right to privacy. They will fully support that right if it's company's violating your privacy (especially, if they are American because protectionism) but in contrast, the German will give itself as many powers as it can to spy on its own citizens and those abroad." This.

That's only double standards if one considers states and companies as being in the same position. A state and a company have vastly different goals. A state should care for its citizens, this includes protections against threats to public safety (terror, organized crime) and surveillance is a tool in the box for that. A company on the other hand, would have no issues fleecing people and abusing their power for profit…

The problem starts if the state wants to save money and skills in intelligence to work around common challenges of anonymous services. The real criminals attacking the constitution often can invest time and money into unbreakable anonymization, such things mostly hinder easy access to privacy by the normal citizen like me.

The german government has really a long record of distrusting anonymization starting with ISDN mixes and denouncing their users. But also little things like one time credit cards seem to be restricted only because it would take an extra step to link the data in a real criminal case.

And regarding data protection: it was big on paper in germany for a long time but only because nearly nobody was actually sued. Now everyone shits their pants here about the GDPR because you at least there are fines ( the rules did not change much). At the same time even with the GDPR we only trusted other german corps with data as corrupt or leaky they may be and not other Europeans.

I agree with the OP that there are double standards here. But mostly it is just a history great theoretical ethics combined with technical incompetence and the deep national feeling of moral superiority...

Re: The German Problem with Tor

#100

I ran an exit node about a decade ago. There are no freedom-fighting journalists in repressed countries using TOR. There are only pornographers, BitTorrent users, crypto-haxxing "Z3r0cools" who use it to feel like they are doing something crypto-haxxy, and botnet command and controllers. Countries in which TOR will be useful treat TOR users as de-facto criminals or block it altogether. Using TOR in a totalitarian sta…

> When you point out that TOR fails in its primary purpose: non-attributable access to information or communications in totalitarian regimes you get scorn.

It's my understanding that the subjects of totalitarian regimes use software such as Ultrasurf [1], and not TOR. I agree that TOR is not very useful in practice, but it seems misleading to state that without mentioning the success of the alternatives.

[1] https://ultrasurf.us/

Post reply on HN