Live data from Hacker News

Tor Browser 12.0

blog.torproject.org

211–220 of 230 posts

Re: Tor Browser 12.0

#211

Earlier quoted context omitted.

It is, in my case. All my system updates run over Tor. I do it to generate noise.

This is one of the main reasons why I keep using Tor daily. The more people use Tor for normal browsing, the less interesting it becomes to be a Tor user, the better the anonymity for everyone else.

Would tor be better off if a major (millions of users) free software or browser vendor added always-on tor exit nodes to their releases?

The only solution to this problem that I can see is massive no opt-out adoption until a tipping point is reached.

Re: Tor Browser 12.0

#212
post #184

Earlier quoted context omitted.

> people who otherwise seem to have tinfoil hats claiming that it’s not needed because Tor provides enough protection I've been on the side of advocating for it, but the other side isn't making an obviously ridiculous argument. The onion protocol itself negotiates an end-to-end cryptographic session, authenticated by the onion site's public key, between the onion site and the end user. There's not cleartext traffic s…

No, v3 isn't TLS either. TLS is only used as a connector between hops (so the client connect to a node using TLS, and the nodes connect to each other using TLS), but that is it. (I think, if I'm wrong do tell me. I didn't go check the spec)

OK, I checked and it's indeed still not TLS.

https://gitlab.torproject.org/tpo/core/torspec/-/blob/main/r...

I think the main question would be: are there cryptographic attacks that a rendezvous server could do that wouldn't work against TLS?

Re: Tor Browser 12.0

#213

Earlier quoted context omitted.

Just keep in mind that your VPN/SSH provider now has the same visibility your ISP did.

Using a reputable VPN who claims no logs is much better than an ISP who gladly hands over logs.

Using a reputable VPN who claims no logs still places immense trust in that VPN provider. If you're a journalist or political dissident, it's possible your life is resting on that trust.

Alternatively, You -> ISP -> Tor -> VPN and paying with Monero obtained over Tor without ever having disclosed your ID or any revealing info means:

• Your ISP knows who you are, but not what you're doing (no anonymity, yes privacy). The connection to tor establishes privacy from ISP.

• Your Tor exit node sees you're connecting to a VPN, but does not know who you are, or what you're doing (yes anonymity, yes privacy). The routing of Tor establishes anonymity, but not privacy from the exit node. The connection to the VPN establishes privacy from the exit node.

• Your VPN provider knows a bit about what you're doing, but not who you are (yes anonymity, less privacy)

This offers additional protection if your VPN provider is compromised / lying about logging (you have no way to verify at any given moment, only that they weren't in past incidents that have gone to court, but this is no guarantee they can't be compelled to start logging your connections).

This also offers additional protection if your guard node and exit node are compromised, which is sufficient to deanonymize tor users.

What it does not offer protection against is all ISP's involved selling netflow metadata to a single party who uses timing and packet sizes to correlate traffic across all of these connections, like Team Cymru does with their Pure Signal Recon product (formerly called Augury).

If that scares you, I'd encourage you to look up what company actually owns and operates torproject's website, and how many contracts they have with governments, too.

Re: Tor Browser 12.0

#214

Earlier quoted context omitted.

> It also doubles as a way for the US government to surveil anyone seeking to evade surveillance as well. Supposing they own now enough Tor node, which the Wikipedia link is unclear about

It seems like a reasonable claim judging by how much easier and cheaper it is to spin up 10s of thousands of nodes than it was a decade ago. Even a wealthy person with a miniscule fraction of the US defense budget could do the same. Idk if there is a technical solution to this attack problem.

There are solutions, but they come at a steep cost with regards to usability, so would shrink the anonymity set to what would be an unacceptable level for the uses Tor cares about. The reality is that these attacks, while theoretically possible, require more work and money than the rewards justify (you can't just bulk buy nodes from a provider, Tor doesn't allow connections that route to the same host or close IPs, and does somewhat regularly block relays that were all created suspiciously close chronologically without identifying as the same operator), so are considered an acceptable risk. Snowden was willing to rely on Tor, the rest of us who just want some extra privacy will be just fine.

Re: Tor Browser 12.0

#215

I once spoke with someone who knew someone who ran an exit node in Europe. He told crazy stories with police knocking every once in a while. Also the legal structure to do that was tricky, because you want to avoid the police searching your house; you'd also like tl spread responsability on multiple shoulders. So you have to create a kind of non-profit organization and run the exit node through that. It's very hard w…

It's surprising to me that those people haven't been arrested yet. People get raided for far lesser offenses compared to running Tor exit nodes.

Exit nodes are a mistake. The web is a lost cause by now. Most sites already consider access through Tor to be abuse. Exit nodes are also the focus of the deanonymization attacks that I've seen. The Tor hidden service network should be strengthened instead. We should launch hidden services instead of web sites.

Re: Tor Browser 12.0

#216

The inescapable fact about Tor is that its traffic patterns make you stand out prominently. Just the fact you’re using it automatically makes you interesting and worthy of a closer look. All well and good if you’re just maintaining a cookie recipe site on the dark web, but it’s rarely ever that, is it?

> but it’s rarely ever that, is it? Maybe I'm unique, but my dark net activity is usually pretty tame. The number one reason I use Tor is because browsing onion sites reminds a bit more of how the web used to be in the late 1990s. Lot's of garbage of course, but a lot more serendipitous discovery than the web today. Because of its anonymous nature Onion sites are inherently resistant to being swallowed whole by adver…

> I know it's wishful thinking, but I often hope for a parallel web to really thrive on Tor.

Me too. Wish every blog and web site out there was a hidden service instead. Especially this one.

Re: Tor Browser 12.0

#217
post #114

Earlier quoted context omitted.

Stop using those services. This is a clear message that you cannot use them privately.

C'mon, for a forum of hackers that's a pretty lame answer, isn't it? :P

People from a forum of hackers should be above depending on Big Tech corporations for anything. Easier said than done but it should still be the general goal.

Re: Tor Browser 12.0

#218

I once spoke with someone who knew someone who ran an exit node in Europe. He told crazy stories with police knocking every once in a while. Also the legal structure to do that was tricky, because you want to avoid the police searching your house; you'd also like tl spread responsability on multiple shoulders. So you have to create a kind of non-profit organization and run the exit node through that. It's very hard w…

I'm running exits since about 9 months. Have been running non exits for over a decade before. The exits are run by a non-profit (a Swiss Verein) and use the recommended setup like described in the blog post. The ISP knows it's an exit, it has a page on port 80 describing it and a PTR record that contains tor-exit. No contact with the police till now. If you would like to support the Tor network but don't want to run…

While supporting funding more nodes is a noble goal another concern I consider overlooked is the potential 'centralisation' of nodes e.g how a large number of Tor nodes are hosted in Germany and near countries and the implications for network surveillance.

Re: Tor Browser 12.0

#219
post #109

Earlier quoted context omitted.

A colleague at a former academic job was questioned by campus police because he was one of a handful of people on the university network connected to TOR when a bomb threat was submitted (I forget how, though) from an IP address running a TOR exit node. Bomb threats from students were pretty common during exams, so after the cops saw that it was our very privacy conscious dev ops guy they didn't pursue him as a suspe…

Sometimes it goes the other way too. In my high school, a handful of kids wore all black every day. They were harmless valley girls/guys if you spoke with them. I figured they _wanted_ to be seen as a threat. Why would someone make a legit bomb threat? Isn't the point of the bomb for it to explode?

The replies have reminded me to mention that I shouldn't judge so quickly and that a handful of those all-black-clothes-all-day-regardless-of-weather school mates were and some still are my friends. I still believe there is a message that is trying to be delivered via one's threads but it can be a plethora of messages rather than just "fear me". EOM.

Re: Tor Browser 12.0

#220

Earlier quoted context omitted.

Could we maybe not on this website use the term glowie considering it's explicitly sourced from a neo nazi and a phrase involving the n word. seems like maybe not real in line with HN rules....

I thought glowie was a term used to describe undercover FBI/CIA agents. It's in frequent use in leftist (communist/anarchist, not liberal democrat) forums. Is there actual substance behind this claim of its origins or is it yet another tired attempt to rewrite language for no particular reason?

[dead]
Post reply on HN