Earlier quoted context omitted.
Does this apply to snowflake relays?
The whole point of Snowflake relays is that nobody knows about them. If Akamai knows about it, then it failed.
Tor in 2022
61–70 of 85 posts
Re: Tor in 2022
#62Earlier quoted context omitted.
Basically, this. Until Tor provides human-readable and -memorable addresses again, I'm considering it a deprecated project. I asked them about it at a talk when V3 was first being introduced, and they said they're working on a solution. Since then... ::crickets::
How could you accomplish this without some sort of registration?
geti2p.net also has community registrars for .i2p domains and includes a built in hosts file of many of the sites, this involves a level of trust in the registries.
Re: Tor in 2022
#63Earlier quoted context omitted.
I'm still not understanding why the 15 year history of communities was not able or willing to act on the 13 months of warning, and months of discussion before that. There was more than ample time to prepare. Surely you don't expect a project like Tor to simply ignore security forever going forward because "people still use it"? Should Tor just stay V2, security be damned? I don't think Tor's main goal is to ensure yo…
I just don't get GP's point. If the workings of the system compromise its entire premise, of course they upgrade the system so that it matches the original intentions. It's like they shouldn't have deprecated old SSL and TLS versions, because some web services still only use those. I can't imagine an active community having trouble with this.
You are all making it sound like this isn't some big deal: that people just needed to "get their act together"... but how do you rebuild the world wide web after breaking every link in the web? Whose job is it even to fix every single link on every single page and stored in every single comment in every single database?
Now, you can certainly argue that the old system was broken by insecurity and thereby had to die. But that just means the entire concept of onion services was some temporary art project more than a platform on which people could build the kind of ecosystem we have on the "normal" world wide web. At best, it means that people needed to come up with some extremely different way of thinking about what those .onion addresses really were, as they were clearly more like IP addresses than hostnames.
I personally can't help but think there could have been some better transition plan. Like maybe a mechanism where people can leave cross-signed redirects from v2 to v3 domains, and maybe even they would only be honored if signed before some date, or maybe there is a disambiguation dialog for competing redirects that also shows the time the redirect was published (these being attempts to deal with "in the future someone could crack this and start making arbitrary redirects for any old site").
But that clearly didn't happen and now that entire ecosystem is dead. Maybe it will rebuild, and maybe one day it will be stronger than it is now, but frankly... when that happens, wouldn't you expect people to start pointing out that the cryptography of the ECC curve they are using is now subject to breaking by quantum computers or whatever we have in another 15 years? Maybe they will handle that transition better, or maybe the mere thought of that will serve as a lesson to not rebuild inside that design.
Truly, though, a design that doesn't take this into consideration from the beginning is inherently flawed. As I noted in passing earlier: these .onion names were clearly more like IP addresses, and so you needed some kind of translation later on top of that to provide later portability. As much as I often hate on the current players in "decentralized DNS" (for various reasons that they could have avoided), that's the kind of concept that clearly is going to win the day going forward.
Re: Tor in 2022
#64Tor in 20202: We've succesfully killed off 90% of all actually used (as opposed to botnet) tor onion services and we're happy about it. We're protecting our end users from themselves by forcing the removal of Tor v2 protocol from the codebase. We don't care because onion services were never really something we cared about, just an add-on to trick people into thinking Tor was a real network worth building a community…
Basically, this. Until Tor provides human-readable and -memorable addresses again, I'm considering it a deprecated project. I asked them about it at a talk when V3 was first being introduced, and they said they're working on a solution. Since then... ::crickets::
This is a very non trivial problem https://en.wikipedia.org/wiki/Zooko%27s_triangle
Re: Tor in 2022
#65Earlier quoted context omitted.
The whole point of Snowflake relays is that nobody knows about them. If Akamai knows about it, then it failed.
I've never heard of snowflake relays. What are they?
Re: Tor in 2022
#66Honest question: What would be the use case for Tor, as is compromised[1] and painfully slow (judging from my personal experience, using it in the US and Asia, across the years). Is there any occasion where it will be better to use Tor than your self-hosted VPN? 1- https://restoreprivacy.com/tor/
A point-by-point look of your source is a bit much for these comments (and they raise some great points that I either agree with or can't thoroughly rebut), but there's some interesting things in there that make me question the poster. They exclaim against being accused of spreading FUD, but use extremely emotional language and talk in absolutes when the reality is much less clear. For example, they say " 2017 court…
You Tor to your VPN, you don't VPN to Tor.
Re: Tor in 2022
#67Earlier quoted context omitted.
A point-by-point look of your source is a bit much for these comments (and they raise some great points that I either agree with or can't thoroughly rebut), but there's some interesting things in there that make me question the poster. They exclaim against being accused of spreading FUD, but use extremely emotional language and talk in absolutes when the reality is much less clear. For example, they say " 2017 court…
"For those who still want to access the Tor network, doing so through a reliable VPN service will add an extra layer of protection while hiding your real IP address." You Tor to your VPN, you don't VPN to Tor.
However, I will say, using Tor to access your VPN strips away much of the benefit of using Tor, to the point that you might as well just use a VPN (sans Tor). I suppose if you want a single-circuit Tor connection that appears to be a static non-Tor IP address, sure. But blindly recommending one way or the other without knowing someone's use case, threat analysis, and risk tolerance is foolish.
Re: Tor in 2022
#68Re: Tor in 2022
#69Earlier quoted context omitted.
I just don't get GP's point. If the workings of the system compromise its entire premise, of course they upgrade the system so that it matches the original intentions. It's like they shouldn't have deprecated old SSL and TLS versions, because some web services still only use those. I can't imagine an active community having trouble with this.
The problem is that the URLs themselves got deprecated: the entire interlinked ecosystem got destroyed. Maybe think of what would happen if all of our current TLDs got deprecated tomorrow, and in a year or two support for them would start getting dismantled. Every single link anyone has ever posted on Hacker News is now broken. Now what? You are all making it sound like this isn't some big deal: that people just need…
An insecure Tor is less than worthless.
Tor is not trying to be a community or be the next geocities. It is an evolving security and privacy project, adapting to the landscape as it needs to, in an effort to anonymize and protect it's users.
>a platform on which people could build the kind of ecosystem we have on the "normal" world wide web
This was never the goal of Tor, and may be the source of your frustrations. Tor has one fundamental mission: deploying free and open source anonymity and privacy technologies.
It is a shame that links will be broken, and it sucks that you feel like something you built up is being torn down. But arguing that it should be kept insecure because of the friends you've made along the way is exactly the opposite of Tor's mission statement.
Re: Tor in 2022
#70Honest question: What would be the use case for Tor, as is compromised[1] and painfully slow (judging from my personal experience, using it in the US and Asia, across the years). Is there any occasion where it will be better to use Tor than your self-hosted VPN? 1- https://restoreprivacy.com/tor/
It comes down to statistics. Using a VPN you are using 1 entity, so all a state actor needs to do is view that one entity's traffic. This may be time consuming and legally challenging if the entity is trustworthy and has servers spread across the globe, but there is still only 1 point that they need to monitor - I suspect many VPN service users are not randomly switching servers. You said "self hosted" VPN which if y…