Live data from Hacker News

Tor is a great sysadmin tool (2020)

jamieweb.net

61–70 of 125 posts

Re: Tor is a great sysadmin tool (2020)

#61

In many ways I think this blog post really makes quite compelling arguments and honestly opened my eyes a bit. One (perhaps mad) idea for more secure access to a machine deep behind many levels of NAT where you, the sysadmin, have lawful access but are fed up with having to have a 12 KB ~/.ssh/config file in order to access it because of your university's overbearing IT department^W^W^W^W network topology, would be t…

You will like this one as well “SSL/SSH Multiplexer” http://www.rutschle.net/tech/sslh/

Re: Tor is a great sysadmin tool (2020)

#62
post #47

Earlier quoted context omitted.

That requires having another publicly accessible box, or trusting ZeroTier though, doesn't it? The onion approach does not.

ZeroTier, Tailscale and such are OSS and have been independently security & crypto audited. I don't know if tailscale has been audited, but since they are a more popular tool I bet they probably are too. They're actually really good tools and would probably be more reliable than tor tbh, I would recommend looking into them.

> ZeroTier, Tailscale and such are OSS and have been independently security & crypto audited.

Both rely on their centralized coordinator servers which can mess with your routes (and thus your traffic) however they please.

ZeroTier has a published (but not OSS) coordinator, but their documentation pushes you towards their SaaS. Tailscale's coordinator is SaaS-only, unless something has changed very recently.

Re: Tor is a great sysadmin tool (2020)

#63
post #20

In many ways I think this blog post really makes quite compelling arguments and honestly opened my eyes a bit. One (perhaps mad) idea for more secure access to a machine deep behind many levels of NAT where you, the sysadmin, have lawful access but are fed up with having to have a 12 KB ~/.ssh/config file in order to access it because of your university's overbearing IT department^W^W^W^W network topology, would be t…

Think from the beginning what will be the end: "I thought your security policy was too overbearing, so I used tor." IT departments make their choices for reasons. The key is to help them understand your use-case, and they'll probably help you through the problem in a way that might limit collateral damage. Source: have seen firewall bypasses (with a pre-shared key) get leveraged as a way to hack an entire university…

A simulated conversation with IT:

"Hey, IT department...I was wondering..."

"No."

Re: Tor is a great sysadmin tool (2020)

#65
I used to have Nessus installed on a NUC that I would just drop into a customer's network closet for a weekend, and monitor remotely.

I hosted the Nessus UI as a Tor Hidden Service, and it worked great. We just cycled the key every quarter for added security, and so that ex-employees wouldn't know where to find it.

Re: Tor is a great sysadmin tool (2020)

#66
post #27

Earlier quoted context omitted.

Obviously, you should plan around this by gathering all the MAC addresses of every machine in the office, and then have your machine spoof through them in rotation. /s

It makes me sad every time I think about it, but Aaron Swartz did this during his saga. Well, sort of: he incremented the MAC address by 1. Point being, it's not foolproof. If some clever undergrad is thinking about dodging the suits, win by fooling them, not by fighting them. If you do insist on fighting, though, start at https://www.whonix.org/wiki/Mental_Model and then read the entire Whonix wiki https://www.whoni…

building a new computer. want to be able to trust it 100% for at least a moment. i can't figure out how to "buy" a trusted copy of any linux and don't have any machines i have 100% trust in (who does), so can't burn it. current plan is to buy a chromebook solely for the purpose of downloading and burning ubuntu. alternatively, buy MSWindows, install on the new machine, burn, and then replace

but this mental exercise has convinced me that security is almost impossible in this day and age

Re: Tor is a great sysadmin tool (2020)

#68
post #20

Earlier quoted context omitted.

Think from the beginning what will be the end: "I thought your security policy was too overbearing, so I used tor." IT departments make their choices for reasons. The key is to help them understand your use-case, and they'll probably help you through the problem in a way that might limit collateral damage. Source: have seen firewall bypasses (with a pre-shared key) get leveraged as a way to hack an entire university…

A simulated conversation with IT: "Hey, IT department...I was wondering..." "No."

Lucky me.

Our IT department goes out the of their way to help us stay sane and productive

- they're making sure most of us can continue to use our favourite Linux distro (I think most Debian/Ubuntu, Fedora and Arch is supported)

- make sure VPN etc works on Linux even if it is not officially supported

- taking time to sit down and debug hard problems (weird issues with WSL2 on one particular Windows laptop) instead of just blaming us engineers

Re: Tor is a great sysadmin tool (2020)

#69
post #66

Earlier quoted context omitted.

It makes me sad every time I think about it, but Aaron Swartz did this during his saga. Well, sort of: he incremented the MAC address by 1. Point being, it's not foolproof. If some clever undergrad is thinking about dodging the suits, win by fooling them, not by fighting them. If you do insist on fighting, though, start at https://www.whonix.org/wiki/Mental_Model and then read the entire Whonix wiki https://www.whoni…

building a new computer. want to be able to trust it 100% for at least a moment. i can't figure out how to "buy" a trusted copy of any linux and don't have any machines i have 100% trust in (who does), so can't burn it. current plan is to buy a chromebook solely for the purpose of downloading and burning ubuntu. alternatively, buy MSWindows, install on the new machine, burn, and then replace but this mental exercise…

One thing that helps a lot in this situation is to plan based on threat model. There’s no such thing as 100% trust, but you can have a computer which is safe for e.g. . It’s pretty crucial to pick one or two specific s and focus only on those.

If you just want to browse the darknet and see what the markets are like, for example, Tor on your current computers is fine.

If you’re wanting to make a purchase and you’re worried that your existing computers will narc on you, your plan of buy laptop + use ubuntu is A+.

If you want a computer to store information on, Edward Snowden style, you’ll need to take increasingly serious steps. Use tails as a baseline. (Note: I’ve been out of the game since 2016, so take this with salt.)

If you’re literally dodging the NSA, you need to put on a full face mask in winter, plan a route to a store you’ve recon’d, buy clothes with cash from goodwill, carry them in a trash bag as you walk out of your neighborhood, sneak in between two houses in the dead of night and put the outfit on + mask, walk to a taxi, have it take you near (but not to) the electronics store, buy yourself a burner phone + a few USB wifi dongles + anything else you want completely unlinkable to you (you’re on cameras), pay for all of it while getting some strange and worried looks that you’re going to rob something, then do the entire process in reverse until you’re back at your house with your untraceable electronics.

I did all that, and even then I was likely making some small mistake that would’ve blown everything.

Yet the city wide surveillance drones (god eye) will still have a nice little record of you that they can ID you with. And you sneaking around in the middle of the night putting on masks will probably get you in serious trouble. It never really occurs to you when you’re doing this sort of thing to stop and consider whether you’re just doing crazy things. (It’s tempting to believe the answer is “no,” especially the more you want to believe it.)

Suffice to say, threat modeling is key, and it’s worth thinking carefully about what exactly you want to accomplish.

Re: Tor is a great sysadmin tool (2020)

#70
post #47

Earlier quoted context omitted.

ZeroTier, Tailscale and such are OSS and have been independently security & crypto audited. I don't know if tailscale has been audited, but since they are a more popular tool I bet they probably are too. They're actually really good tools and would probably be more reliable than tor tbh, I would recommend looking into them.

> ZeroTier, Tailscale and such are OSS and have been independently security & crypto audited. Both rely on their centralized coordinator servers which can mess with your routes (and thus your traffic) however they please. ZeroTier has a published (but not OSS) coordinator, but their documentation pushes you towards their SaaS. Tailscale's coordinator is SaaS-only, unless something has changed very recently.

This is fair.

Their client node software is audited though, and the contents of your packets are not accessible to the router. This is why the amount of the possible meddling is limited to a DoS, AFAICT.

Who audits the Tor nodes that do onion routing is anyone's guess; I suppose ZeroTier is no worse than them.

Post reply on HN