Live data from Hacker News

Tor is a great sysadmin tool (2020)

jamieweb.net

121–125 of 125 posts

Re: Tor is a great sysadmin tool (2020)

#121

Earlier quoted context omitted.

“Because I think I might know better I will act in a disrespectful way, and make someone else’s job harder instead of working with them to solve the problem” You’re not the one who’s phone is going to ring at 3am on Saturday when that Tor node gets compromised. You’re not the one who has to manage the security incident. You’re not the one who has to explain why your security controls and policy did not prevent this f…

I'm curious how you think an SSH service exposed over TOR is going to create a security issue? SSH is exposed all over the public internet.

It bypasses all proxies and interception, and hides all of the traffic contained in the tunnel. This means no traffic logging of the tunneled traffic, no IPS/IDS in front of the SSH service, and no visibility into the SSH traffic itself. If the box with the SSH service isn’t in a DMZ it also compromises network segmentation.

The problem isn’t SSH over TOR being insecure. It is sidestepping all of the security controls in place at your org and not talking to the netsec folks first.

Honestly I would be amazed if any competent netsec folks would even allow TOR outbound by default. I certainly wouldn’t allow it by default in an enterprise environment.

Re: Tor is a great sysadmin tool (2020)

#122
post #86

Earlier quoted context omitted.

One thing that helps a lot in this situation is to plan based on threat model. There’s no such thing as 100% trust, but you can have a computer which is safe for e.g. . It’s pretty crucial to pick one or two specific s and focus only on those. If you just want to browse the darknet and see what the markets are like, for example, Tor on your current computers is fine. If you’re wanting to make a purchase and you’re wo…

> If you’re literally dodging the NSA, you need to... Or just make friends with an developing-world advance-fee scammer, and then pay them to have one of their cash mules buy and send you (that is, an empty house somewhere in your city) a laptop.

Or just buy a used computer at a pawn shop that doesn't keep track of the MAC addresses or serial numbers of its items, and pay in cash.

Re: Tor is a great sysadmin tool (2020)

#123

Earlier quoted context omitted.

To quote Dr. Manhattan, "Without condemning, or condoning, I understand". I am in network security. I have stopped shadow IT, and been a part of it. Your situation seems so ungodly stupid and anathema to the point of IT, that the remaining courses of action should be the following. Thoroughly document via email your attempts at explaining requirements to Netsec, to document in writing their objections, to do your bes…

This is a diverging motivations issue. Many people are not in a stable career such that they can hang around and do upper management's job for them by "expensively failing so as to demonstrate IT's failures". Academics and PHD students in particular live from grant to grant. They can't afford to waste grant money "to make a point that IT doesn't work." Reputations - and by extension careers - can be made and unmade w…

I was assuming that the OP was someone who worked in a department IT role, that had to abide by more centralized IT security requirements. You're right that someone who is more transient or less full-time has less motivation to make a long-term point to the administration.

Re: Tor is a great sysadmin tool (2020)

#124

Earlier quoted context omitted.

To quote Dr. Manhattan, "Without condemning, or condoning, I understand". I am in network security. I have stopped shadow IT, and been a part of it. Your situation seems so ungodly stupid and anathema to the point of IT, that the remaining courses of action should be the following. Thoroughly document via email your attempts at explaining requirements to Netsec, to document in writing their objections, to do your bes…

This is a diverging motivations issue. Many people are not in a stable career such that they can hang around and do upper management's job for them by "expensively failing so as to demonstrate IT's failures". Academics and PHD students in particular live from grant to grant. They can't afford to waste grant money "to make a point that IT doesn't work." Reputations - and by extension careers - can be made and unmade w…

Quite. IT people in universities have jobs for life. The overwhelming majority of academics -- often including many professors -- do not.

Re: Tor is a great sysadmin tool (2020)

#125

Earlier quoted context omitted.

you _could_ use your other device (the one you're connecting from) as the controller. whomst amongst us doesn't have a 3rd machine or VPS?

Your other device doesn't have a public IP address either.

Doesn't need one!
Post reply on HN