Live data from Hacker News

Tor in 2022

blog.torproject.org

41–50 of 85 posts

Re: Tor in 2022

#41
post #31

Earlier quoted context omitted.

I'm still not understanding why the 15 year history of communities was not able or willing to act on the 13 months of warning, and months of discussion before that. There was more than ample time to prepare. Surely you don't expect a project like Tor to simply ignore security forever going forward because "people still use it"? Should Tor just stay V2, security be damned? I don't think Tor's main goal is to ensure yo…

Because tor v2 and v3 are not compatible. You can't just make all the links everyone ever made on any site, or entries in any search index, suddenly point to a new URL. You can announce v2 is going to disappear and say that everyone should try to port what they can, but most don't. Only the big sites and their users actually have any pseudo-continuity through their efforts. And even then all the links stop working.

The fact that people didn't port is not an argument that they shouldn't have ported.

Tor is primarily a security and privacy project. Arguing that they should keep an insecure version because people decided to ignore the security implications of that insecure version is an awful argument. Especially when those people had well over a year to execute.

Your use case for Tor seems to be unrelated to the projects goals.

Re: Tor in 2022

#42

Earlier quoted context omitted.

Are you sure it was supposed to provide "cover for spies"? AFAIK onion routing was an invention of the US Naval Research Laboratories and was public from the beginning. If you want "spies" to use it, you don't want them connecting to known gateways. High anonymity (simplex) is why number stations are still a thing.

Do number stations still a thing? Here in Europe there are just some beacons that broadcast the same message daily but no other activity whatsoever.

They're still a thing as recently as a year or two ago when I looked into it. They're "perfect" in that the receiver can't be identified from the message or its channel (other than catching him with his radio), and that the message cannot be reversed (encoded w/ a one time pad). So they're hard to replace.

Re: Tor in 2022

#43
post #2

isn't tor under the control of US intel agencies now? is there an alternative darknet?

Not for us common folk, I don't think so.

Sure, they can listen in on you all they want, but what good is any of that if they can't use it against you in a court of law?

Re: Tor in 2022

#44
Honest question: What would be the use case for Tor, as is compromised[1] and painfully slow (judging from my personal experience, using it in the US and Asia, across the years). Is there any occasion where it will be better to use Tor than your self-hosted VPN?

1- https://restoreprivacy.com/tor/

Re: Tor in 2022

#45

Earlier quoted context omitted.

Do number stations still a thing? Here in Europe there are just some beacons that broadcast the same message daily but no other activity whatsoever.

They're still a thing as recently as a year or two ago when I looked into it. They're "perfect" in that the receiver can't be identified from the message or its channel (other than catching him with his radio), and that the message cannot be reversed (encoded w/ a one time pad). So they're hard to replace.

One time pads aren't perfect. The same secret has to be stored on both sides and can be compromised from either side.

OTP has to be delivered preserving secrecy. Transmitting a public key only needs to preserve integrity.

Re: Tor in 2022

#46
post #2

isn't tor under the control of US intel agencies now? is there an alternative darknet?

Not for us common folk, I don't think so. Sure, they can listen in on you all they want, but what good is any of that if they can't use it against you in a court of law?

Ever hear of parellel construction?

https://en.wikipedia.org/wiki/Parallel_construction

Re: Tor in 2022

#47
post #2

isn't tor under the control of US intel agencies now? is there an alternative darknet?

In regards to your second question, yes, there is I2P. https://geti2p.net It's better than Tor in a few ways, in particular how it handles DDOS attacks. I2P is also more focused on facilitating hidden services (eepsites) than being a clearnet proxy. There's also Yggdrasil, although it doesn't seem particularly concerned about anonymity. https://yggdrasil-network.github.io/

https://letsdecentralize.org

Here are a few options.

Re: Tor in 2022

#48
post #33

Earlier quoted context omitted.

Basically, this. Until Tor provides human-readable and -memorable addresses again, I'm considering it a deprecated project. I asked them about it at a talk when V3 was first being introduced, and they said they're working on a solution. Since then... ::crickets::

How could you accomplish this without some sort of registration?

The way it was already accomplished previously: short addresses, which, although not easy, are possible to remember.

16 characters is doable, especially if it starts with 5-8 letters of word(s). 56 characters is not realistic.

Re: Tor in 2022

#49

Earlier quoted context omitted.

Tor was originally written by US intel agencies specifically to provide cover for spies. The release of the software to the public was specifically to provide plausible deniability for those spies. So there's always going to be some level of control and knowledge the US has about the network. If your threat model is anything weaker than a hostile nation state then Tor is still probably good enough to use as a darknet…

Are you sure it was supposed to provide "cover for spies"? AFAIK onion routing was an invention of the US Naval Research Laboratories and was public from the beginning. If you want "spies" to use it, you don't want them connecting to known gateways. High anonymity (simplex) is why number stations are still a thing.

> If you want "spies" to use it, you don't want them connecting to known gateways.

The best place to hide a tree is in a forest.

If you have both 'normal' users and spies connecting to this host, who will tell who's the spy?

Re: Tor in 2022

#50

Honest question: What would be the use case for Tor, as is compromised[1] and painfully slow (judging from my personal experience, using it in the US and Asia, across the years). Is there any occasion where it will be better to use Tor than your self-hosted VPN? 1- https://restoreprivacy.com/tor/

A point-by-point look of your source is a bit much for these comments (and they raise some great points that I either agree with or can't thoroughly rebut), but there's some interesting things in there that make me question the poster. They exclaim against being accused of spreading FUD, but use extremely emotional language and talk in absolutes when the reality is much less clear.

For example, they say "2017 court case proves FBI can de-anonymize Tor users", but immediately handwave the how away, because it's classified. Well then, that's not really a strong proof of Tor being compromised -- there are several ways the FBI could de-anonymize Tor users that have nothing to do with Tor itself (people being compromised by javascript, people posting pictures with metadata, people linking back to real-life accounts, people inadvertently posting identifiable information, people posting quasi-identifiable information that is correlated over time, people downloading XYZ that has a beacon in it, etc.)

I also can't help but wonder, if Tor is so thoroughly compromised and just a glowstick, why would the author finish with:

>For those who still want to access the Tor network, doing so through a reliable VPN service will add an extra layer of protection while hiding your real IP address.

If it's compromised to the core, a glowstick for LEA, enables the US government to "do spooky stuff", why bother giving a half-ass endorsement at the end of a hit piece?

Post reply on HN