Live data from Hacker News

Why offer an Onion Address rather than just encourage browsing-over-Tor?

alecmuffett.com

101–110 of 134 posts

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#101
post #12

Earlier quoted context omitted.

the article talks about the research stumbling upon exit nodes performing MITM and other sniffing but does not refer to the exact details. is there a paper for this? only found this paper going over systematic process of exposing bad relays - http://www.cs.kau.se/philwint/spoiled_onions/pets2014.pdf

What research are you talking about? The article talks about at least two different researchers working on separate projects. Here's the link for first one: https://web.archive.org/web/20150705184539/https://chloe.re/...

well, was referring to the research indicated by the title of the article- honeypot setup to detect malicious exit relays.

yes thats the one. interesting, seems they caught 15 unique relays harvesting logins. There seems to be scope to improve reporting and detection of malicious actors like this. They also have a block list on Tor's gitlab repo but doesn't seem to be up to date.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#102
post #86

Earlier quoted context omitted.

They could probably compel you to continue, or forcibly take over the node. Once you're in NSL "we can do anything we want and you can't tell anyone about it" land, being prevented from shutting down your own business or service isn't terribly far-fetched.

The government cannot anyone to work without pay. This seems obvious but it is a constitutional right that has been cited as a reason to not comply with extra-judicial pressure to assist the government with an investigation. This is why some projects do not accept donations and have a canary. Had the authors of Truecrypt been paid, they could had been compelled to modify their source code to the government's will. By…

> it is a constitutional right

Ahem... "terrorism!"

Poof! Now your Constitutional rights no longer exist.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#103
post #93

Earlier quoted context omitted.

It's a tunnel into your internal network. If nation states and/or cyber criminals do control most of tor, then you are opening your internal network to those groups.

So is port forwarding or running any other services, tor is special in absolutely no meaningful respect here.

The OP said "employer," and most people can't port forward at the office without talking to IT.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#104

Earlier quoted context omitted.

So is port forwarding or running any other services, tor is special in absolutely no meaningful respect here.

The OP said "employer," and most people can't port forward at the office without talking to IT.

there are an almost infinite amount of ways to host services from behind firewalls without port forwarding, or any network admin approval. Tor is not special in this regard, nor dangerous due to supposed bad people controlling the network.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#105
post #86

Earlier quoted context omitted.

They could probably compel you to continue, or forcibly take over the node. Once you're in NSL "we can do anything we want and you can't tell anyone about it" land, being prevented from shutting down your own business or service isn't terribly far-fetched.

The government cannot anyone to work without pay. This seems obvious but it is a constitutional right that has been cited as a reason to not comply with extra-judicial pressure to assist the government with an investigation. This is why some projects do not accept donations and have a canary. Had the authors of Truecrypt been paid, they could had been compelled to modify their source code to the government's will. By…

https://www.cfr.org/in-brief/what-defense-production-act grants the US government significant control over the US economy and businesses. As it turns out, we're still at war :-)

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#106
post #63
post #49

Earlier quoted context omitted.

I'm using Tor to access my local network services through hidden services. Since I don't need to hide my IP address I'm going to follow your advice gratefully. Didn't know that's possible.

That's sort of like having backdoor access to your internal network (similar to teredo). Others may use it to gain access to that network. If it's your home, that may be OK to you, but if it is an employer, you may want to obtain approval to do that and be sure all of your hidden services use keys or strong passwords for access.

This is completely incorrect. It is physically impossible to make a connection to a hidden service without the hidden services onion address (I am talking about the current v3 onion addresses, the ones that are 56 characters long). This is thanks to the fact that the onion address itself is the hidden services public key.

If you keep your onion address private then nobody can connect to your hidden service or even know that it exists. Simple as that.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#107

Earlier quoted context omitted.

Could you explain this a bit more? How would this be more open than port forwarding? I don't see how someone could leverage this without exploiting whatever app is hosted as the hidden service?

Yes, it's exactly like port forwarding.

This is incorrect. A Tor hidden service is fundamentally different from port forwarding. If you don't have the hidden services onion address (v3 address) then you physically cannot make a connection to the hidden service. This is because the onion address is the hidden services public key.

You can scan the entire internet for open ports, you can't scan the Tor network for hidden services to connect to unless you already have the hidden services onion addresses.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#108
post #106
post #63

Earlier quoted context omitted.

That's sort of like having backdoor access to your internal network (similar to teredo). Others may use it to gain access to that network. If it's your home, that may be OK to you, but if it is an employer, you may want to obtain approval to do that and be sure all of your hidden services use keys or strong passwords for access.

This is completely incorrect. It is physically impossible to make a connection to a hidden service without the hidden services onion address (I am talking about the current v3 onion addresses, the ones that are 56 characters long). This is thanks to the fact that the onion address itself is the hidden services public key. If you keep your onion address private then nobody can connect to your hidden service or even kn…

It's also "physically impossible" for someone to gain access to a well configured IPSec endpoint, yet we still consider this a point of access that needs appropriate controls and security oversight. There are many, many ways that people collect key material to use to access tunnels to corporate networks. No matter how confident you might be in the technology, you should never provide an access point to a private network without full consideration of the security and compliance implications.

Perhaps the bigger issue though is that Tor at least used to be frequently used by botnets for C2, I'm not in a SOC environment any more so I'm not sure how much that trend has changed. But it's very common for corporate security programs to configure IDS to report on Tor traffic since it's associated with some sort of compromise a good percentage of the time. This does mean you get occasional false positives from normal Tor use to e.g. anonymously access public materials but that's life in a SOC. The point though is that most corporate environments ought to notice this kind of thing happening whether or not it's done with the approval of IT/security.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#109

> Using onion services mitigates attacks that can be executed by possibly-malicious “Tor Exit Nodes” — which, though rare, are not nonexistent Is there any evidence that the majority of exit nodes aren't malicious? There's only 300 or so in the US, 300 or so in Germany, and in other countries even less. What would it take for three letter agencies to compromise most of it? I mean, suppose all of the existing nodes we…

What does compromising the exit do? I thought the layering means you would need to compromise the entire path to do anything.

Because it switches over to the clearnet there, the operator could do stuff like intercept non-https traffic or use a malicious DNS to attempt to MITM https traffic.

Re: Why offer an Onion Address rather than just encourage browsing-over-Tor?

#110

Earlier quoted context omitted.

The only attacks an exit alone can do is sniff all traffic and modify the traffic. There are constant checks done by the Torproject to detect bad exits that modify traffic but sniffing is not detectable of course. But both of those attacks are mitigated by https which most sites support nowadays. Firefox and therefore the Tor Browser also has an option to disable http. [0] And using an .onion service removes this att…

> But both of those attacks are mitigated by https which most sites support nowadays. Unfortunately, not as much as you might hope. For good reasons, the Tor browser doesn't store your browsing history - so there's no 'recently visited sites', no address bar autocomplete, no cached redirects, no cached HSTS, and no colour-changed 'visited' links. So if you're visiting a site that isn't HSTS-preloaded - for example bi…

"... you'd better remember to type in the https:// explicitly ..."

You should use a slug[1] if you need assurance that you’re staying on your vpn/protocol/exit.

It would be very simple to create a "tor only" network slug.

[1] https://john.kozubik.com/pub/NetworkSlug/tip.html

Post reply on HN