Live data from Hacker News

Tor Browser 12.0

blog.torproject.org

181–190 of 230 posts

Re: Tor Browser 12.0

#181
post #37

The inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting and worthy of a closer look. All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?

There is also the inescapable fact that Tor was created by US Intelligence, specifically the US Naval Research Lab[0]. And according to FOIA documents it continues to receive a huge chunk of funding & resources from US Intelligence, particularly from the United States Agency for Global Media (formerly the Broadcasting Board of Governors), which supervises our propaganda channels Voice of America and Radio Free Europe…

That’s probably one of the reasons that TLS over Tor has remained such a tough nut, with people who otherwise seem to have tinfoil hats claiming that it’s not needed because Tor provides enough protection. My opinion is that you want that end to end protection for the same reason you want it on the clearnet - to make so nobody along the way is sniffing your traffic. (that includes both exit nodes and any middle nodes that might be taking advantage of an unknown flaw or bias)

Having a bunch of Tor site certs in your MacOS keychain has its own issues, so what is really needed is a way for Tor browsers to accept those certs directly without using the OS trust stores. The current practice of authenticating the remote site by PGP signature would remain more or less the same - you just wouldn’t have exit nodes sniffing traffic.

I’m also convinced that the whole reason Google has pushed TLS so hard isn’t some noble quest to protect people’s privacy and freedom of speech - it’s more to keep people from blocking their advertisements, which isn’t nearly so sexy an argument, but it has brought good benefits for a lot of people.

Re: Tor Browser 12.0

#182
post #84
post #61

Earlier quoted context omitted.

This part appears to be missing from the Tor website: > 2,500 pages of correspondence — including strategy and contracts and budgets and status updates — between the Tor Project and its main funder, a Central Intelligence Agency spinoff now known as the Broadcasting Board of Governors (BBG). These files show incredible cooperation between Tor and the regime change wing of the US government. So the documents acquired…

It's pretty obvious that TOR is a helpful tool if you're doing spyshit in foreign countries.

That's what _they_ want you to think!

(finally I can say that and it may in fact actually be true for once! hahaha)

Re: Tor Browser 12.0

#183

Earlier quoted context omitted.

> The inescapable fact about Tor is that its traffic patterns make you stand out prominently. I'm curious as to how it stands out. I can imagine a few things, like an ISP seeing traffic to known TOR intermediary nodes, or maybe analyzing packets to look for some sort of handshake? > Just the fact you’re using it automatically makes you interesting and worthy of a closer look. Sort of. But what would looking do? What…

It's known from leaks that showing an interest in Tor is enough to get you on an NSA list. But this list was so incredibly broad that anyone with an interest in technology was/is probably on it, diminishing its usefulness to actually discriminate anyone. https://www.propublica.org/article/heres-one-way-to-land-on-...

I mean how do they do it? In terms of the technology/ fingerprinting approach.

Re: Tor Browser 12.0

#184
post #37

Earlier quoted context omitted.

There is also the inescapable fact that Tor was created by US Intelligence, specifically the US Naval Research Lab[0]. And according to FOIA documents it continues to receive a huge chunk of funding & resources from US Intelligence, particularly from the United States Agency for Global Media (formerly the Broadcasting Board of Governors), which supervises our propaganda channels Voice of America and Radio Free Europe…

That’s probably one of the reasons that TLS over Tor has remained such a tough nut, with people who otherwise seem to have tinfoil hats claiming that it’s not needed because Tor provides enough protection. My opinion is that you want that end to end protection for the same reason you want it on the clearnet - to make so nobody along the way is sniffing your traffic. (that includes both exit nodes and any middle nodes…

> people who otherwise seem to have tinfoil hats claiming that it’s not needed because Tor provides enough protection

I've been on the side of advocating for it, but the other side isn't making an obviously ridiculous argument. The onion protocol itself negotiates an end-to-end cryptographic session, authenticated by the onion site's public key, between the onion site and the end user. There's not cleartext traffic sent between a Tor exit node and the onion site or anything!

My argument in favor of TLS to onion sites was that, at least as of onion protocol v2, the cryptographic session was not itself TLS, and its security and threat model hadn't been as extensively reviewed as those of TLS. So it might turn out that there was something suboptimal there that the rendezvous server could then use to perform a sophisticated cryptographic attack.

I don't know if this is still true of onion protocol v3 or if the client-to-onion-site session is now also based on TLS.

Re: Tor Browser 12.0

#185
post #37

Earlier quoted context omitted.

There is also the inescapable fact that Tor was created by US Intelligence, specifically the US Naval Research Lab[0]. And according to FOIA documents it continues to receive a huge chunk of funding & resources from US Intelligence, particularly from the United States Agency for Global Media (formerly the Broadcasting Board of Governors), which supervises our propaganda channels Voice of America and Radio Free Europe…

That’s probably one of the reasons that TLS over Tor has remained such a tough nut, with people who otherwise seem to have tinfoil hats claiming that it’s not needed because Tor provides enough protection. My opinion is that you want that end to end protection for the same reason you want it on the clearnet - to make so nobody along the way is sniffing your traffic. (that includes both exit nodes and any middle nodes…

You seem to mix up a lot of stuff here. The Tor Project thinks TLS for onion services is unneeded because they ARE end to end encrypted by design. The address itself is an ed25519 public key. And exit nodes are not involved in connecting to an onion service at all.

For connections to the clearnet it was always highly recommended to only use TLS and recent Tor browsers have now finally enabled https only mode that displays a big warning if you try to connect to a http server.

Re: Tor Browser 12.0

#186
“ In May 2020 we found a group of Tor exit relays that were messing with exit traffic. Specifically, they left almost all exit traffic alone, and they intercepted connections to a small number of cryptocurrency exchange websites. If a user visited the HTTP version (i.e. the unencrypted, unauthenticated version) of one of these sites, they would prevent the site from redirecting the user to the HTTPS version (i.e. the encrypted, authenticated version) of the site. If the user didn't notice that they hadn't ended up on the HTTPS version of the site (no lock icon in the browser) and proceeded to send or receive sensitive information, this information could be intercepted by the attacker.”

This seems like a dumb way to exploit an http downgrade attack. Far better, would be to redirect the user to a fake looking https site and collect the user data there.

As with many such attacks, a password manager can help mitigate or WebAuthN. Though I am not sure how that would play with Tor and the privacy guarantees users are looking for.

Re: Tor Browser 12.0

#188

Earlier quoted context omitted.

I've been running exit nodes in europe for years and not even a call from the police, what's wrong with me? huh? ;) I do regularly handle abuse complaints by blocking IPs or other actions.

Have you been blocked by any major services? I've heard horror stories from colleagues of their static IP address eventually being blocked from their bank.

Running an exit from your home IP is a very, very bad idea so he most likely has rented a server somewhere and is running the exit node there.

Re: Tor Browser 12.0

#189

Earlier quoted context omitted.

Rather than playing coy, you should tackle the challenging part of your argument head-on: tell us why you think Tor is different from other technologies that are routinely abused. That would actually be a substantive contribution to the discussion.

Why do I have to tell you this when it should be instantly obvious: Tor is literally designed to obfuscate the identity of people. A coffee machine isn't.

I'm curious if you are also opposed to encryption in general. How about https? Should all traffic be http?

Re: Tor Browser 12.0

#190

The inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting and worthy of a closer look. All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?

> if you’re just maintaining a cookie recipe site on the dark web

Some people just want privacy. No need to have an specific "cookie recipe" activity: they would just browse the New York Times, but in full reassurance of anonymity - as they believe is normal.

(And by the way: "«brows[ing] the New York Times»" - as a sequence of actions - is not a neutral activity, but already a profiling one.)

Post reply on HN