Live data from Hacker News

Tor Browser 12.0

blog.torproject.org

201–210 of 230 posts

Re: Tor Browser 12.0

#201

Earlier quoted context omitted.

For example, once or twice people called me (somehow) and asked why I was hacking their websites. I tried to explain, but I doubt I convinced anyone.

May I ask: That wasn't enough for you to stop operating a Tor node? People were abusing others thanks to your specific personal efforts and you just said: "eh, it's still worth it". How do you determine that it's still worth it?

Some statistics from one of my servers regarding Tor abuse. From 1130 abuse IPs in my http access log 4 are Tor exit nodes and from the 1905 ssh bruteforce attacker IPs 3 are Tor exit nodes. Stop operating Tor nodes would therefore reduce the abuse by basically nothing but take Tor from the people that need it.

>eh, it's still worth it

Yes it's totally worth it.

Re: Tor Browser 12.0

#202
Perhaps, if we encourage more people to use privacy preserving tools like Tor browser, signal, etc., then privacy for everyone will be normalized again. One can only hope

Re: Tor Browser 12.0

#203

I once spoke with someone who knew someone who ran an exit node in Europe. He told crazy stories with police knocking every once in a while. Also the legal structure to do that was tricky, because you want to avoid the police searching your house; you'd also like tl spread responsability on multiple shoulders. So you have to create a kind of non-profit organization and run the exit node through that. It's very hard w…

It is widely suspected that the US NSA runs a large number of Tor exit nodes themselves. Tor was originally developed by a US military research lab and received additional funding under the justification that it would help dissidents in China and North Korea evade their country's censorship and surveillance. It also doubles as a way for the US government to surveil anyone seeking to evade surveillance as well. See th…

> It also doubles as a way for the US government to surveil anyone seeking to evade surveillance as well.

On a technical level, exit node operators aren't supposed to be able to trace the origin of data flowing through them... so this indicates a failure of protocol.

Re: Tor Browser 12.0

#204
post #203

Earlier quoted context omitted.

It is widely suspected that the US NSA runs a large number of Tor exit nodes themselves. Tor was originally developed by a US military research lab and received additional funding under the justification that it would help dissidents in China and North Korea evade their country's censorship and surveillance. It also doubles as a way for the US government to surveil anyone seeking to evade surveillance as well. See th…

> It also doubles as a way for the US government to surveil anyone seeking to evade surveillance as well. On a technical level, exit node operators aren't supposed to be able to trace the origin of data flowing through them... so this indicates a failure of protocol.

Unless you control enough nodes. Tor was never designed to be 100% surveillance proof

Re: Tor Browser 12.0

#205

Earlier quoted context omitted.

I've been running exit nodes in europe for years and not even a call from the police, what's wrong with me? huh? ;) I do regularly handle abuse complaints by blocking IPs or other actions.

Have you been blocked by any major services? I've heard horror stories from colleagues of their static IP address eventually being blocked from their bank.

I'm sure they have been blocked, many times. Some online services simply fetch the tor exit node IP lists from the tor project and block them all pre-emptively.

The thing is that I rotate my tor nodes every other month, manually. No pipeline setup for this yet. So I destroy old VPS and create new ones with the same signing key and family in the node info.

I suspect you're talking about running an exit node at home, or on an IP-address that matters. That's a stupid thing to do.

Re: Tor Browser 12.0

#206

Earlier quoted context omitted.

How is HN anti-tor? Everyone can read your comment. Wdym by "vouching"? Also, HN deletes your account when you them send a mail as stated in the FAQ. It always sucks to delete accounts with user comments, as it destroys context in old threads. As spiders crawl the web humans should consider anything they post online as undeletable. If you send HN the beforementioned, there is a chance that I can still browse your pos…

> Everyone can read your comment. Wdym by "vouching"? There's "showdead" profile setting that allows you to see flagged comments, and enough "karma" allows you to vouch for hidden-by-default content. It's one of those hidden (somewhat) features: https://github.com/minimaxir/hacker-news-undocumented#flaggi...

Thank you for the link, I didn't know about half of the features listed there!

Re: Tor Browser 12.0

#207

Earlier quoted context omitted.

Rather than playing coy, you should tackle the challenging part of your argument head-on: tell us why you think Tor is different from other technologies that are routinely abused. That would actually be a substantive contribution to the discussion.

Why do I have to tell you this when it should be instantly obvious: Tor is literally designed to obfuscate the identity of people. A coffee machine isn't.

>Why do I have to tell you this when it should be instantly obvious

Because it's only instantly obvious until you consider it for a moment. By your logic, literally any privacy-preserving technology, be it disposable email services or *69 on your telephone, are morally unjustifiable.

Re: Tor Browser 12.0

#208
Somehow I knew if I looked at these comments, I'd see the top poster be something like "I know someone, who knows someone, who heard from someone else that this one time in bandcamp..."

Re: Tor Browser 12.0

#209

Earlier quoted context omitted.

It is widely suspected that the US NSA runs a large number of Tor exit nodes themselves. Tor was originally developed by a US military research lab and received additional funding under the justification that it would help dissidents in China and North Korea evade their country's censorship and surveillance. It also doubles as a way for the US government to surveil anyone seeking to evade surveillance as well. See th…

> It also doubles as a way for the US government to surveil anyone seeking to evade surveillance as well. Supposing they own now enough Tor node, which the Wikipedia link is unclear about

It seems like a reasonable claim judging by how much easier and cheaper it is to spin up 10s of thousands of nodes than it was a decade ago. Even a wealthy person with a miniscule fraction of the US defense budget could do the same.

Idk if there is a technical solution to this attack problem.

Re: Tor Browser 12.0

#210

I once spoke with someone who knew someone who ran an exit node in Europe. He told crazy stories with police knocking every once in a while. Also the legal structure to do that was tricky, because you want to avoid the police searching your house; you'd also like tl spread responsability on multiple shoulders. So you have to create a kind of non-profit organization and run the exit node through that. It's very hard w…

I once tweeted something like: > "For those of you interested in running an exit node, just be safe. Always remember to run it via your company's VPN to ensure the safety of those making passage through." The engagement was nuts and the sheer amount of people who use ToR but were unfamiliar with what a statement actually says was frightening.

I hope that engagement was people telling you that in fact: No don't do that.

https://gitlab.torproject.org/tpo/community/team/-/wikis/Exp...

Post reply on HN