Live data from Hacker News

Tor Browser 10

blog.torproject.org

71–80 of 106 posts

Re: Tor Browser 10

#71
post #57

Earlier quoted context omitted.

>> It is not recommended by anyone to depend on tor against that threat model. That depends as much on the use case as the threat. Traffic analysis attacks require traffic . Short burst communication via tor (chat/email/bot control commands etc) are not traced as easily as large file downloads or random web browsing. Attacks on the client (malware) are also very hardware dependant. A target using the same Tor client…

How you figure we would heard about it? I mean the only reason we know they can break RSA 50% of the time was because of Snownden and that was like 10 years ago or so. I mean these people are really good at keeping things secret, I remember reading books written in the late 80's that still said the first use of computers was calculating artillery tables, not codebreaking.

I thought that was, they can/could break HTTPS half the time, and that was the Logjam attack.

Re: Tor Browser 10

#72
post #68
post #59

Earlier quoted context omitted.

There's way too much noise in this measurement for it to be seriously meaningful, unless ownership of tor was itself a crime.

Maybe in the west that'd be true- since we can freely trade information over the public internet, TOR doesn't have much utility. Let's say you're in a more totalitarian government that censors more information- TOR might look like a practical solution there, and might have people using it for more practical purposes.

> since we can freely trade information over the public internet

No we can’t.

Re: Tor Browser 10

#73
post #57

Earlier quoted context omitted.

>> It is not recommended by anyone to depend on tor against that threat model. That depends as much on the use case as the threat. Traffic analysis attacks require traffic . Short burst communication via tor (chat/email/bot control commands etc) are not traced as easily as large file downloads or random web browsing. Attacks on the client (malware) are also very hardware dependant. A target using the same Tor client…

How you figure we would heard about it? I mean the only reason we know they can break RSA 50% of the time was because of Snownden and that was like 10 years ago or so. I mean these people are really good at keeping things secret, I remember reading books written in the late 80's that still said the first use of computers was calculating artillery tables, not codebreaking.

> I mean the only reason we know they can break RSA 50% of the time was because of Snownden and that was like 10 years ago or so.

Edward Snowden's revelations were about seven years ago, and did not include anything about the NSA breaking RSA encryption or signatures 50% of the time or any other amount. Who knows where you got that from, but not Edward Snowden.

> I remember reading books written in the late 80's that still said the first use of computers was calculating artillery tables, not codebreaking.

That would be because it was true. The purpose of the Difference Engine and of early mechanical calculating machines that were actually built at the time was construction of tables.

Colossus (which was used for breaking Lorenz) is an early electronic computer, but certainly not the first such computer and it isn't a stored program computer (to change what Colossus does it's necessary to physically disassemble it) so it's not actually part of the lineage of stored program computers we use today.

The Ultra Secret was published in 1974 - after that point the fact that Colossus existed and everything else about war work at Bletchley was not a secret. So Ultra was kept secret for just over thirty years.

Re: Tor Browser 10

#74
post #46
post #19

Earlier quoted context omitted.

For users wanting to prevent their ISP from sniffing around then tor works as intended. Against advertisers it also work decently as a self cleaning browsers that constantly change its IP address. For developers and sysadmins that want to get an outside look at their own services or investigate third party websites (like fraudulent lookalike) it work pretty effective with some caveats. It also works mostly fine again…

> Against national-level intelligence agency, "citizen scores", and whistleblowers employed within such agencies, the protection granted by tor may be very far from 100%. It is not recommended by anyone to depend on tor against that threat model. Are there any alternatives then, that do work against this threat model? It seems like a lot of the real need for such a tool is for journalists and activists who do need pr…

I think you misunderstand. For such adversaries, Tor is good enough for what it does, but not sufficient. You probably want something like TAILS as part of a whole package of serious real-world OpSec.

Re: Tor Browser 10

#75
post #47
post #18

Earlier quoted context omitted.

There are some ways to mitigate some of the threats that you mention. Using Qubes or Whonix could prevent network access to other programs. The unencrypted requests can be blocked by turning on the EASE option in the HTTPS-Everywhere preferences. Tor doesn't have any way to protect against global adversaries performing timing analysis or attacks though.

Yeah I'm surprised HTTPSEverywhere with EASE isn't a part of the Tor browser. Maybe a contributor on here can comment?

It is though. Add HTTPSEverywhere to the toolbar using customize, and you will get the option to enable "Encrypt All Sites Eligible". Working as of Tor Browser 10.0 (ESR 78.3)

Version: 2020.8.13 Rulesets version for EFF (Full): 2020.9.14 Rulesets version for SecureDropTorOnion: 2020.7.30

Re: Tor Browser 10

#76
post #41

Earlier quoted context omitted.

Why are people always called "proud people"? Are there no people embarrassed of their country?

Most Brits.

Confirmed. Also possible to be embarrassed of your individual component countries like England or Northern Ireland.

For example here's a famous response to the idea of being proud to be Scottish: https://www.youtube.com/watch?v=G1tJJO_pVvQ

Re: Tor Browser 10

#77
post #66

Earlier quoted context omitted.

That GitHub page in particular, versus any GitHub page? That'd involve a TLS break, no?

Yeah they need to hack or infiltrate Github, or get a warrant for your data.

Good thing Microsoft isn’t voluntarily in the PRISM progra-

Re: Tor Browser 10

#78
post #52

Earlier quoted context omitted.

with or without downloading Tor I say its safe to assume everyone here is already under some kind of monitoring like we're all potential customers/criminals

We’re all on many lists. What matters is where you rank on it.

I would think that not being on any of lists would be so suspicious on its own, it would warrant adding to a list.

Re: Tor Browser 10

#79
post #69
post #66

Earlier quoted context omitted.

That GitHub page in particular, versus any GitHub page? That'd involve a TLS break, no?

Just did some research, and you're right! TLS obscures the URL by default. I didn't know that. Only nuance being that an attacker can draw conclusions about the length of the URL- which won't be very helpful on Github.

TLS alone is not sufficient. Fortunately, Github is also on the HSTS preload list.

Re: Tor Browser 10

#80
post #64

Earlier quoted context omitted.

You can use pluggable transports to camouflage your traffic (they're already built into the Tor Browser, e.g. meek, snowflake, ...). To get Tor in the first place in a censored/risky place you can get it from the official GetTorBrowser repository on Github: https://github.com/TheTorProject/gettorbrowser (There are additional links to GitLab, Archive.Org, Google Drive)

The state could easily track who accesses that GitHub page, if they control the ISP.

Especially in places like China where the Internet is heavily censored and Microsoft already has experience complying with the government's policies. https://www.wired.com/story/china-github-free-speech-covid-i...
Post reply on HN