Live data from Hacker News

Tor in 2022

blog.torproject.org

21–30 of 85 posts

Re: Tor in 2022

#21

Tor in 20202: We've succesfully killed off 90% of all actually used (as opposed to botnet) tor onion services and we're happy about it. We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. We don't care because onion services were never really something we cared about, just an add-on to trick people into thinking Tor was a real network worth building a community…

>We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase.

All of your links describe why V3 is more secure and superior to V2. Are you whining about the increased security, or am I misunderstanding your post?

If I'm not misunderstanding, why was the over one year of warnings and multiple years of discussions not enough time to prepare?

Re: Tor in 2022

#22

Tor in 20202: We've succesfully killed off 90% of all actually used (as opposed to botnet) tor onion services and we're happy about it. We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. We don't care because onion services were never really something we cared about, just an add-on to trick people into thinking Tor was a real network worth building a community…

Basically, this. Until Tor provides human-readable and -memorable addresses again, I'm considering it a deprecated project.

I asked them about it at a talk when V3 was first being introduced, and they said they're working on a solution. Since then... ::crickets::

Re: Tor in 2022

#23
post #20

Tor in 20202: We've succesfully killed off 90% of all actually used (as opposed to botnet) tor onion services and we're happy about it. We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. We don't care because onion services were never really something we cared about, just an add-on to trick people into thinking Tor was a real network worth building a community…

> https://metrics.torproject.org/hidserv-dir-onions-seen.html Your link shows that there were about 170k v2 onion addresses in September 2020, while there were about 550k v3 onion addresses at that same date. The trends were only pointing up for v3 addresses while pointing down for v2 ones.

I can't blame you for just skimming, but you've come away with a mistaken interpretation.

Yes, there are a ton of v3 onions created quite suddenly but they don't stick around for long and aren't associated with human people. The Tor project technical blog on v3 onion services suggests most of the v3 services are "barely used" and setup to merely act as slave services for a malicious botnet. https://blog.torproject.org/v3-onion-services-usage . Human people actually run websites (and other services) from v2 addresses and there are far more of them even now than actual human used v3 addresses if you can extrapolate anything from onion descriptor information in the hidden service directory.

Re: Tor in 2022

#24
post #5

Not really related to the article, but what's the origin of picutres like the one used in the article? A few years ago https://www.humaaans.com/ was all the rage, is this something like this too? I can't imagine that each of these images is individually produced, I feel like they are assembled, but I can't find the origin. Edit: answering my own question, https://blush.design/ (link found on the humaans page) has thi…

No post body was provided.

Re: Tor in 2022

#25
post #2

isn't tor under the control of US intel agencies now? is there an alternative darknet?

In regards to your second question, yes, there is I2P.

https://geti2p.net

It's better than Tor in a few ways, in particular how it handles DDOS attacks. I2P is also more focused on facilitating hidden services (eepsites) than being a clearnet proxy.

There's also Yggdrasil, although it doesn't seem particularly concerned about anonymity.

https://yggdrasil-network.github.io/

Re: Tor in 2022

#26
post #18
post #9

Earlier quoted context omitted.

Tor never claimed resiliency against large-scale traffic correlation attacks. Anyone who can look at a sufficient portion of all internet traffic has a good chance of deanonymizing TOR users. The Snowden revelations could lead one to believe that the US is sniffing enough traffic to make this viable, but it's anyone's guess if they collect and synchronize enough data to make deanonymization of TOR users viable. I2P a…

I wish more people ran TOR nodes. I intend to run one when I can.

To be fair it's not like you can run one from your home connection. I mean you could, but it wouldn't be a good idea, unfortunately.

Re: Tor in 2022

#27
post #26
post #18

Earlier quoted context omitted.

I wish more people ran TOR nodes. I intend to run one when I can.

To be fair it's not like you can run one from your home connection. I mean you could, but it wouldn't be a good idea, unfortunately.

Running an exit relay from home would be a very bad idea, and if your IP frequently changes you might not be picked as guard relay. But I don't see why you couldn't run a middle relay from home, as long as you don't have a traffic cap.

Re: Tor in 2022

#28
post #26
post #18

Earlier quoted context omitted.

I wish more people ran TOR nodes. I intend to run one when I can.

To be fair it's not like you can run one from your home connection. I mean you could, but it wouldn't be a good idea, unfortunately.

Running an intermediate/middle node is generally safe. You want to avoid running an exit node.

Re: Tor in 2022

#29
post #26

Earlier quoted context omitted.

To be fair it's not like you can run one from your home connection. I mean you could, but it wouldn't be a good idea, unfortunately.

Running an intermediate/middle node is generally safe. You want to avoid running an exit node.

Running a middle node got my IP banned from some services, even services provided by my ISP.

Re: Tor in 2022

#30
post #21

Tor in 20202: We've succesfully killed off 90% of all actually used (as opposed to botnet) tor onion services and we're happy about it. We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. We don't care because onion services were never really something we cared about, just an add-on to trick people into thinking Tor was a real network worth building a community…

> We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. All of your links describe why V3 is more secure and superior to V2. Are you whining about the increased security, or am I misunderstanding your post? If I'm not misunderstanding, why was the over one year of warnings and multiple years of discussions not enough time to prepare?

Removing the v2 code from clients and falsely stating v2 onions aren't valid URLs is lying to users to protect them from a potential future threat. But that protection comes at the cost: the destruction of the entire 15 year history of communities and interlinking and search indices for onionland. To protect the community they have destroyed it.

A v3 community might come in the future, and I hope it will, but right now v3 .onions are pretty much just bots and a few big names that have created new v3 services. The rest is botnet v3 .onions.

What I want, what everyone in the tor project comment thread on the depreciation post wants, is for v2+v3. Not just v2. Even now most tor relays support v2 and will until the tor project puts out a version consensus flag that blocks older tor. But they can't do that any time soon because most tor infrastructure still supports v2.

Post reply on HN