Live data from Hacker News

Why offer an Onion Address rather than just encourage browsing-over-Tor?

alecmuffett.com

81–90 of 134 posts

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#81

Earlier quoted context omitted.

Could you explain this a bit more? How would this be more open than port forwarding? I don't see how someone could leverage this without exploiting whatever app is hosted as the hidden service?

Yes, it's exactly like port forwarding.

Are you sure? Don't an attacker need knowledge of the onion address, which is almost unguessable?

But with client authentification that wouldn't be a problem anyways because only chosen clients get access.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#82
post #54

Earlier quoted context omitted.

Hidden services are very easy to configure (the basic config, if you want to be as anonym as possible you have to do more). Install tor, add a few lines to config, done. And: You don't have to change your firewall settings at all. Nothing is exposed to the clearnet. You can also make your service be accessible only to certain clients which have a certificate. I consider this very secure.

> You can also make your service be accessible only to certain clients which have a certificate. I consider this very secure. Are you talking about this? https://community.torproject.org/onion-services/advanced/cli...

Yes, client authentification it is called.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#84

Earlier quoted context omitted.

I'm not clear from the article how having an onion address helps website operators who receive abusive traffic through Tor. Perhaps some of that abusive traffic will come in via the onion address instead, but presumably such an operator will want to continue serving their regular site to Tor exit nodes as well, so I don't see how it would actually mitigate anything, nor make the malicious traffic easier to segregate…

> I'm not clear from the article how having an onion address helps website operators who receive abusive traffic through Tor. No, it's not clear. Also "abusive traffic" is vague. Are you mainly concerned with shitposters, trolls, DOS attacks? > What am I missing? Maybe you're not missing it, but essentially it's a behavioural/social rather than technical challenge. Most abusers, ones that technical changes can addres…

Back when I was staff on (pre-madness) freenode providing an onion address was pretty much the only way we could afford to support tor at all given the moderation resources available.

Smaller networks often (usually regretfully) end up blocking tor entirely if they don't have the capacity to set up such infrastructure.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#85
post #24

I think the only legit reason (assuming your clearnet site is using HSTS) is that .onion site reduces the risks of users screwing up. And i suppose better performance if you don't have to use exit bandwidth (i would guess, dont actually know) Users are bad at security. If they fail to set up tor, .onion links don't work, so it acts as a barrier against users shooting themselves in the foot. This is counterbalanced by…

It's good motivation to start using client certs instead of passwords.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#86

Earlier quoted context omitted.

Can you just shutdown your nodes or can they force you to continue? Best practice for relay operators is to just stop the operation altogether if the authorities force you to attack the users.

They could probably compel you to continue, or forcibly take over the node. Once you're in NSL "we can do anything we want and you can't tell anyone about it" land, being prevented from shutting down your own business or service isn't terribly far-fetched.

The government cannot anyone to work without pay.

This seems obvious but it is a constitutional right that has been cited as a reason to not comply with extra-judicial pressure to assist the government with an investigation.

This is why some projects do not accept donations and have a canary.

Had the authors of Truecrypt been paid, they could had been compelled to modify their source code to the government's will.

By not accepting payment, they are protecting themselves.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#87

Earlier quoted context omitted.

Even if every exit node in the US is operated by private people or organizations, courts can compel the node owners to work with the government and not talk about it.

Courts can't compel you not to talk. They can merely punish you after-the-fact. So if you're talking about "everyone in a giant group of people" and doing it routinely, existence of those secret subpoenas seem like they'd get leaked eventually. Especially if it's hard to tell which of the 300 people leaked it.

Any of these TLAs will love figuring out who leaked it, and it usually isn’t hard.

And knowing this, the jail time or personal life destruction that would almost inevitably occur isn’t worth it for almost anyone.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#88
post #15

Earlier quoted context omitted.

Aren't there warrant canaries set up to prevent this? Every website that can be compelled to behave that way should have one.

> Aren't there warrant canaries set up to prevent this? No, because the police will tell you to not tell anyone about the court order. If you do so (for example using a warrant canary), you will be in big trouble. Those canaries were always a convenient fiction, almost to the point of it being entirely in question whether or not this fiction was created in good faith.

They cannot compel someone to re-authorize a deadman switches' canary.

If the canary doesn't receive a signed message within X amount of days, the canary sings.

Nobody can force someone to do work or self-incriminate.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#89

Earlier quoted context omitted.

Exit node is where the tor-encrypted path ends and traffic goes to the clearnet.

What’s the point of any of it then to a paranoid user?

Got me - it looks like a decently effective honeypot though for ‘paranoid but hasn’t thought it all the way through’

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#90

> The first benefits are authenticity and availability: if you are running Tor Browser and if you click/type in exactly the proper Onion address, you are guaranteed to be connected to what you expect — or not at all. What? Writing raw onion addresses is like writing raw IPv6 addresses. Nobody can remember then and check them. What is easier > https://nytimes.com or > ej3kv4ebuugcmuwxctx5ic7zxh73rnxt42soi3tdneu2c2em55…

Neither. Either can be mistyped. Nobody enters addresses directly anymore. Either you google them or you get them from bookmarks.

Onion addresses that are mistyped are almost certainly an invalid address.

It is not possible to squat onion domains for typo errors like you can clearnet addresses.

Similar to bitcoin, one character swapped breaks the hash-checksum, making the address 99.99999999% likely to be invalid.

Post reply on HN