Live data from Hacker News

Tor Browser 12.0

blog.torproject.org

101–110 of 230 posts

Re: Tor Browser 12.0

#101

All comments here focus on extreme cases: The police viewing you as a possible suspect, FBI becoming interested in you etc. Here is a much more mundane problem: Using Tor (even a VPN) while logging in to most big Silicon Valley firma that make money with your data (LinkedIn, Facebook, Tinder etc.) will result in your profile being suspended REAL FAST with the only way out to upload your gov't ID, i.e. complete deanon…

I struggle with the very same problem. Even connecting a real physical SIM won't protect accounts from suspension. This is crazy because it isn't based on behavior on the platform (like posting too much or liking too much) but merely on the IP and browser fingerprint.

Unfortunately, no solutions in sight.

Re: Tor Browser 12.0

#103

I once spoke with someone who knew someone who ran an exit node in Europe. He told crazy stories with police knocking every once in a while. Also the legal structure to do that was tricky, because you want to avoid the police searching your house; you'd also like tl spread responsability on multiple shoulders. So you have to create a kind of non-profit organization and run the exit node through that. It's very hard w…

> Does anybody know more about how exit nodes are being run?

They have a good list of points on the Tor site. The most important ones are usually to distance yourself from the exit node and make it obvious what it does so you don't get entangled into whatever is going through the node.

https://blog.torproject.org/tips-running-exit-node/

Re: Tor Browser 12.0

#104
post #16

Earlier quoted context omitted.

I believe the Tor feature of Brave is an optional setting, so I assume only a small fraction of their MAU use it.

It’s not a setting, it’s like their version of an incognito tab. You can right click a link to “open in tor”

Wow this is really cool. I need to look into Brave again.

Re: Tor Browser 12.0

#105
post #16

Earlier quoted context omitted.

I believe the Tor feature of Brave is an optional setting, so I assume only a small fraction of their MAU use it.

It’s not a setting, it’s like their version of an incognito tab. You can right click a link to “open in tor”

Afaik, it does not use Tor from within the browser, but uses a proxy server into Tor. That could have changed though.

Re: Tor Browser 12.0

#106

The inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting and worthy of a closer look. All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?

a closer look maybe, but unless they break Tor they'll only have a close look at your timing traffic. if you're worried, you could use a popular VPN to connect to Tor - using a VPN is less interesting. also, P2P app developers could consider running non-exit nodes in their clients for popular apps. there shouldn't be legal risks unless you're running an exit node, and this adds more noise to the signal of Tor users.

I once tried running a non-exit node and quickly found that a lot of sites would blacklist my IP regardless. Can't recommend.

Re: Tor Browser 12.0

#107
post #16

Earlier quoted context omitted.

I believe the Tor feature of Brave is an optional setting, so I assume only a small fraction of their MAU use it.

It’s not a setting, it’s like their version of an incognito tab. You can right click a link to “open in tor”

They also have private windows without Tor and the users probably found out that Tor takes quite longer and works only half the time compared to the ordinary private window, so I wouldn't get my hopes up that it is adopted massively.

(Still, it's great they have done that.)

Re: Tor Browser 12.0

#108

I once spoke with someone who knew someone who ran an exit node in Europe. He told crazy stories with police knocking every once in a while. Also the legal structure to do that was tricky, because you want to avoid the police searching your house; you'd also like tl spread responsability on multiple shoulders. So you have to create a kind of non-profit organization and run the exit node through that. It's very hard w…

I ran one in my student housing wardrobe a decade or so ago. I too have some stories, but no one ever met up with me in the flesh.

Come on then, no need to be coy.

Re: Tor Browser 12.0

#109

The inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting and worthy of a closer look. All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?

A colleague at a former academic job was questioned by campus police because he was one of a handful of people on the university network connected to TOR when a bomb threat was submitted (I forget how, though) from an IP address running a TOR exit node. Bomb threats from students were pretty common during exams, so after the cops saw that it was our very privacy conscious dev ops guy they didn't pursue him as a suspe…

Sometimes it goes the other way too. In my high school, a handful of kids wore all black every day. They were harmless valley girls/guys if you spoke with them. I figured they _wanted_ to be seen as a threat.

Why would someone make a legit bomb threat? Isn't the point of the bomb for it to explode?

Re: Tor Browser 12.0

#110

Just FYI that HN is very anti-tor. I made this account via Tor just now to prove the point. It will be dead by default (unless someone "vouches" for it). It's a very user-hostile stance that HN takes (along with not letting you delete your account). It really makes you wonder what they're doing with all this data? Doxxing is almost a given.

I created my account here using a MitM Squid SSL Bump proxy in a VPS provider and posted from that proxy for a few years. Once in a blue moon I would get rate limited, I assume because this site was being abused. AFAIK my posts were never affected by using my VPS proxies. VPS IP's and Tor exit node IP's are often treated as equally hostile by many sites but not here. I avoid Tor because every time I tried it there was just too much latency for me and I don't like someone else controlling the exit node.

I eventually stopped using the proxy here on HN not because of this site but Cloudflare and Google would grief me on so many sites that people submit here which made it hard for me to review them and submitting everything to archive.ph is time consuming. I keep the MitM proxy around in case I need to go to a very hostile website or if I want to leave a funny PTR DNS record in their logs.

Post reply on HN