Live data from Hacker News

Tor in 2022

blog.torproject.org

31–40 of 85 posts

Re: Tor in 2022

#31
post #21

Earlier quoted context omitted.

> We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. All of your links describe why V3 is more secure and superior to V2. Are you whining about the increased security, or am I misunderstanding your post? If I'm not misunderstanding, why was the over one year of warnings and multiple years of discussions not enough time to prepare?

Removing the v2 code from clients and falsely stating v2 onions aren't valid URLs is lying to users to protect them from a potential future threat. But that protection comes at the cost: the destruction of the entire 15 year history of communities and interlinking and search indices for onionland. To protect the community they have destroyed it. A v3 community might come in the future, and I hope it will, but right n…

I'm still not understanding why the 15 year history of communities was not able or willing to act on the 13 months of warning, and months of discussion before that. There was more than ample time to prepare.

Surely you don't expect a project like Tor to simply ignore security forever going forward because "people still use it"? Should Tor just stay V2, security be damned? I don't think Tor's main goal is to ensure your community stays friends; the goals are a bit loftier.

I wonder if you hold the same views on any other security-related thing like cryptography or password storage. We'd still be at 8 character, lower-case only, truncated passwords "because people built infrastructure for it".

Re: Tor in 2022

#32
post #29

Earlier quoted context omitted.

Running an intermediate/middle node is generally safe. You want to avoid running an exit node.

Running a middle node got my IP banned from some services, even services provided by my ISP.

Indeed, some CDNs like Akamai do not bother distinguishing relays from exit nodes and just ban everything.

Re: Tor in 2022

#33

Tor in 20202: We've succesfully killed off 90% of all actually used (as opposed to botnet) tor onion services and we're happy about it. We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. We don't care because onion services were never really something we cared about, just an add-on to trick people into thinking Tor was a real network worth building a community…

Basically, this. Until Tor provides human-readable and -memorable addresses again, I'm considering it a deprecated project. I asked them about it at a talk when V3 was first being introduced, and they said they're working on a solution. Since then... ::crickets::

How could you accomplish this without some sort of registration?

Re: Tor in 2022

#34
post #29

Earlier quoted context omitted.

Running a middle node got my IP banned from some services, even services provided by my ISP.

Indeed, some CDNs like Akamai do not bother distinguishing relays from exit nodes and just ban everything.

Does this apply to snowflake relays?

Re: Tor in 2022

#35
post #3

> Tracked as KAX17, the threat actor ran at its peak more than 900 malicious servers part of the Tor network, which typically tends to hover around a daily total of up to 9,000-10,000. https://therecord.media/a-mysterious-threat-actor-is-running...

One thing i didn't catch is how they are sure that this is "one" great actor. Surely some of these servers were registered with the same fake mail address, but it seems that otherwise they are spread around the world and pretty anonymous. Did i miss something?

I asked this same question on HN a short time ago. The modifications are advanced and not public, so anyone using them is suspected of being related to the same entity. There are also potentially other signature-worthy variables being observed as well.

Re: Tor in 2022

#36
post #2

isn't tor under the control of US intel agencies now? is there an alternative darknet?

Tor was originally written by US intel agencies specifically to provide cover for spies. The release of the software to the public was specifically to provide plausible deniability for those spies. So there's always going to be some level of control and knowledge the US has about the network. If your threat model is anything weaker than a hostile nation state then Tor is still probably good enough to use as a darknet…

Are you sure it was supposed to provide "cover for spies"? AFAIK onion routing was an invention of the US Naval Research Laboratories and was public from the beginning. If you want "spies" to use it, you don't want them connecting to known gateways. High anonymity (simplex) is why number stations are still a thing.

Re: Tor in 2022

#37
post #31

Earlier quoted context omitted.

Removing the v2 code from clients and falsely stating v2 onions aren't valid URLs is lying to users to protect them from a potential future threat. But that protection comes at the cost: the destruction of the entire 15 year history of communities and interlinking and search indices for onionland. To protect the community they have destroyed it. A v3 community might come in the future, and I hope it will, but right n…

I'm still not understanding why the 15 year history of communities was not able or willing to act on the 13 months of warning, and months of discussion before that. There was more than ample time to prepare. Surely you don't expect a project like Tor to simply ignore security forever going forward because "people still use it"? Should Tor just stay V2, security be damned? I don't think Tor's main goal is to ensure yo…

Because tor v2 and v3 are not compatible. You can't just make all the links everyone ever made on any site, or entries in any search index, suddenly point to a new URL.

You can announce v2 is going to disappear and say that everyone should try to port what they can, but most don't. Only the big sites and their users actually have any pseudo-continuity through their efforts. And even then all the links stop working.

Re: Tor in 2022

#38
post #31

Earlier quoted context omitted.

Removing the v2 code from clients and falsely stating v2 onions aren't valid URLs is lying to users to protect them from a potential future threat. But that protection comes at the cost: the destruction of the entire 15 year history of communities and interlinking and search indices for onionland. To protect the community they have destroyed it. A v3 community might come in the future, and I hope it will, but right n…

I'm still not understanding why the 15 year history of communities was not able or willing to act on the 13 months of warning, and months of discussion before that. There was more than ample time to prepare. Surely you don't expect a project like Tor to simply ignore security forever going forward because "people still use it"? Should Tor just stay V2, security be damned? I don't think Tor's main goal is to ensure yo…

I just don't get GP's point. If the workings of the system compromise its entire premise, of course they upgrade the system so that it matches the original intentions. It's like they shouldn't have deprecated old SSL and TLS versions, because some web services still only use those. I can't imagine an active community having trouble with this.

Re: Tor in 2022

#40

Earlier quoted context omitted.

Tor was originally written by US intel agencies specifically to provide cover for spies. The release of the software to the public was specifically to provide plausible deniability for those spies. So there's always going to be some level of control and knowledge the US has about the network. If your threat model is anything weaker than a hostile nation state then Tor is still probably good enough to use as a darknet…

Are you sure it was supposed to provide "cover for spies"? AFAIK onion routing was an invention of the US Naval Research Laboratories and was public from the beginning. If you want "spies" to use it, you don't want them connecting to known gateways. High anonymity (simplex) is why number stations are still a thing.

Do number stations still a thing? Here in Europe there are just some beacons that broadcast the same message daily but no other activity whatsoever.
Post reply on HN