Live data from Hacker News

Tor in 2022

blog.torproject.org

71–80 of 85 posts

Re: Tor in 2022

#71
post #57

Earlier quoted context omitted.

It's one added layer of protection. Combine Tor with a VPN. If your life is on the line with your content the more layers of protection the better.

Why not tor over tor then?

"You're very clever, young man, very clever- but it's tortles all the way down!"

Re: Tor in 2022

#72
post #6
post #5

Not really related to the article, but what's the origin of picutres like the one used in the article? A few years ago https://www.humaaans.com/ was all the rage, is this something like this too? I can't imagine that each of these images is individually produced, I feel like they are assembled, but I can't find the origin. Edit: answering my own question, https://blush.design/ (link found on the humaans page) has thi…

It's called Alegria and all hip tech companies use it. It's pretty widely hated https://www.reddit.com/r/starterpacks/comments/jwsagt/big_te... https://www.reddit.com/r/starterpacks/comments/groh5e/big_te... https://youtu.be/lFb7BOI_QFc

I once heard it called "toddlers' bauhaus" and I'm sticking with that.

Re: Tor in 2022

#73
post #26
post #18

Earlier quoted context omitted.

I wish more people ran TOR nodes. I intend to run one when I can.

To be fair it's not like you can run one from your home connection. I mean you could, but it wouldn't be a good idea, unfortunately.

I've been running a Tor relay from my home for a decade, at least. It's not an exit relay. Never had any issue.

Re: Tor in 2022

#74
post #26

Earlier quoted context omitted.

To be fair it's not like you can run one from your home connection. I mean you could, but it wouldn't be a good idea, unfortunately.

Running an exit relay from home would be a very bad idea, and if your IP frequently changes you might not be picked as guard relay. But I don't see why you couldn't run a middle relay from home, as long as you don't have a traffic cap.

You can run an exit relay from home, at least in the US. There are some ISPs (mostly on the East coast, afaict) that may not help you, but most of them seem to understand how the laws work.

In other countries you may not have such luck.

Re: Tor in 2022

#75
post #3

> Tracked as KAX17, the threat actor ran at its peak more than 900 malicious servers part of the Tor network, which typically tends to hover around a daily total of up to 9,000-10,000. https://therecord.media/a-mysterious-threat-actor-is-running...

One thing i didn't catch is how they are sure that this is "one" great actor. Surely some of these servers were registered with the same fake mail address, but it seems that otherwise they are spread around the world and pretty anonymous. Did i miss something?

Another mistake Tor tends to make is assuming 1 IP = 1 server. In theory someone could point 9,000 IP addresses at a single server. In practice this would be obvious when the bandwidth for it sucks, but it could easily be a single cluster of servers in one location with a bunch of addresses routing to it.

Re: Tor in 2022

#76

Honest question: What would be the use case for Tor, as is compromised[1] and painfully slow (judging from my personal experience, using it in the US and Asia, across the years). Is there any occasion where it will be better to use Tor than your self-hosted VPN? 1- https://restoreprivacy.com/tor/

Wow there's so much FUD, hyperbole, and rigged language there. "Interesting" exchanges alright.

They go ahead and make FBI and backdoors bold to shock the reader but conveniently rest of the context is left out. The actual context being Roger giving a talk about Tor at one of these conferences where you also have government entities voice their (guess guess) desire for backdooring and wiretapping the internet (while tech people from the industry aren't convinced). The same shit you see discussed openly in the public all the time anyway, probably just with more pleading from the FBI because it's so hard to solve crime without industry's help. Nothing unusual here. The wording of this fudpiece sounds like it's trying to implicate the Tor developer in planting backdoors for the FBI, which is not at all what the exchange is about if you read the context.

"Tor privately tips off the federal government to security vulnerabilities before alerting the public" is also complete FUD. I'm so glad I read the whole stack of FOIA'd documents before this text.

The context here is that BBG (Broadcasting Board of Governors) is using Tor to circumvent censorship in places like Iran, China, Saudi Arabia, and Russia. Alright you can call that a propaganda arm of the US government if you're so willing, but anyway, Tor is one of the tools they rely on. They need Tor to circumvent censorship, so they need to address vulnerabilities in Tor that make it easy to censor.

This "vulnerability" isn't one that FBI uses to catch a drug dealer or a hacker, it's a vulnerability that makes it easy to fingerprint and block Tor traffic. Now Tor's use has historically been quite easy to detect and block (see e.g. this FAQ entry from 2008 [1]) and fixing that has been a long road, I don't know where exactly they stand today. The "vulnerability" is just one among many and the possibility of fingerprinting TLS has been mentioned in the FAQ. It's not the kind of vulnerability you would have to scream and alert the public to (they should've already been aware that it is possible identify and block Tor traffic). Rather, it's something they should quietly research and figure out a solution to and hopefully stay ahead of the game w.r.t. regimes that may attempt to block Tor.

Discussing the draft proposal for fixing this TLS fingerprint vuln with the people who they are working together with to keep Tor useful in Iran etc. is exactly what the Tor project ought to do! The fact that these people happen to be employed by the U.S. Government doesn't seem particularly relevant. But suuure, "privately tipping off the feds to a vuln while keeping the public in the dark" is a nice way to twist it.

Here's the thing, there are issues with Tor, there are issues with anything because there is no technical solution to perfect anonymity. I would not bet my life on Tor. But knowing what it's good for and what its limits are, Tor is a very useful tool, and IMHO it can only get better if it gets more users and more relays. I would always recommend being vigilant and looking out for bugs, backdoors, and other sketchy stuff, but this fud piece just doing a disservice against itself with all the hyperbole. It sounds more like they've got an axe to grind.

[1] https://web.archive.org/web/20080415073019/https://wiki.torp...

> The original Tor design was easy to block if the attacker controls Alice's connection to the Tor network --- by blocking the directory authorities, by blocking all the relay IP addresses in the directory, or by filtering based on the fingerprint of the Tor TLS handshake. Some government-level firewalls could easily launch this type of attack, which would make the whole Tor network no longer usable for the people behind the firewalls.

Sect. 7.1:

> Note that all your local ISP can observe now is that you are communicating with Tor nodes. Similarly, servers in the Internet just see that they are being contacted by Tor nodes

See also the linked DRAFT "Design of a blocking-resistant anonymity system" https://web.archive.org/web/20080322054926/http://www.torpro...

Re: Tor in 2022

#77
post #63

Earlier quoted context omitted.

I just don't get GP's point. If the workings of the system compromise its entire premise, of course they upgrade the system so that it matches the original intentions. It's like they shouldn't have deprecated old SSL and TLS versions, because some web services still only use those. I can't imagine an active community having trouble with this.

The problem is that the URLs themselves got deprecated: the entire interlinked ecosystem got destroyed. Maybe think of what would happen if all of our current TLDs got deprecated tomorrow, and in a year or two support for them would start getting dismantled. Every single link anyone has ever posted on Hacker News is now broken. Now what? You are all making it sound like this isn't some big deal: that people just need…

Thanks for the long message, I now get the point. However necessary the change, it's sure to drive some people away for good. Some kind of redirection mechanism would have handled this nicely.

Now that I'm thinking about this, a browser extension could handle this - with JavaScript enabled of course. It could come with a V2->V3 host mapping, and then scan the page and fix the links within. Or maybe do the mapping when the link is clicked or otherwise interacted with.

Re: Tor in 2022

#78
post #69
post #63

Earlier quoted context omitted.

The problem is that the URLs themselves got deprecated: the entire interlinked ecosystem got destroyed. Maybe think of what would happen if all of our current TLDs got deprecated tomorrow, and in a year or two support for them would start getting dismantled. Every single link anyone has ever posted on Hacker News is now broken. Now what? You are all making it sound like this isn't some big deal: that people just need…

> Now, you can certainly argue that the old system was broken by insecurity and thereby had to die. But that just means the entire concept of onion services was some temporary art project An insecure Tor is less than worthless. Tor is not trying to be a community or be the next geocities. It is an evolving security and privacy project, adapting to the landscape as it needs to, in an effort to anonymize and protect it…

> It is a shame that links will be broken, and it sucks that you feel like something you built up is being torn down.

FWIW, your comment is confusing either identities or motives: I have never myself built a .onion site, in no small part because I saw clearly a long time ago that the ecosystem was doomed: I carefully consider all of the tech I use for "sustainability". I am merely someone who is sitting on the sidelines, attempting to--and apparently succeeding, based on your sibling comment--at providing some context and translation in a disagreement.

> Tor is not trying to be a community or be the next geocities. ... This was never the goal of Tor, and may be the source of your frustrations.

I even have a lot of sympathy for your attempt here to seemingly agree with me that the .onion ecosystem could never be taken seriously for a "world wide web"-like ecosystem... but, then you seem to fail to realize the context of me responding to someone who was willing to believe that .onion could work and felt that the websites in question merely should have somehow updated sooner (forgetting that the web is, well, a "web" > But arguing that it should be kept insecure because of the friends you've made along the way is exactly the opposite of Tor's mission statement.

I absolutely did no such thing, and it is disingenuous to claim such after literally quoting me providing and admitting the opposite argument in my comment. If you re-read my point, I even sketch out a potential securable transition plan for a "road not taken" that doesn't involve Tor being "kept insecure". The real travesty, frankly, is that Tor failed to understand the implications of what they had built and prepare people for the future.

Re: Tor in 2022

#80
post #78
post #69

Earlier quoted context omitted.

> Now, you can certainly argue that the old system was broken by insecurity and thereby had to die. But that just means the entire concept of onion services was some temporary art project An insecure Tor is less than worthless. Tor is not trying to be a community or be the next geocities. It is an evolving security and privacy project, adapting to the landscape as it needs to, in an effort to anonymize and protect it…

> It is a shame that links will be broken, and it sucks that you feel like something you built up is being torn down. FWIW, your comment is confusing either identities or motives: I have never myself built a .onion site, in no small part because I saw clearly a long time ago that the ecosystem was doomed: I carefully consider all of the tech I use for "sustainability". I am merely someone who is sitting on the sideli…

You continually mentioned community, and seemed to portray yourself as an operator that refused to update to V3 to maintain your V2 community. I tried to empathize with that. My bad.

The 'friends along the way' was a cheeky comment referring to the communities you mentioned here and in other comments several times. It is certainly not the opposite of what you argued -- you are arguing for community and interoperability, and argued that Tor should maintain the insecure version for that interoperability.

To wit, you said "What I want, what everyone in the tor project comment thread on the depreciation post wants, is for v2+v3.".

This is equal to "Maintain the insecure version, do not deprecate it, because the community wants it".

We're obviously of two separate minds here. I didn't mean to step on toes or seem disingenuous. Just frustrated when I see people complain about necessary security upgrades, which were known over a year in advance, in a security product.

Post reply on HN