Live data from Hacker News

Tor: From the Dark Web to the Future of Privacy

direct.mit.edu

31–40 of 100 posts

Re: Tor: From the Dark Web to the Future of Privacy

#31

Earlier quoted context omitted.

Those are fair points. I would argue that it's not the tech that's weak, but that the protection that powerful people get from institutions, local networks, status in their communities etc. often give them so much access to practical power that they essentially don't need anonymity - because these institutions protect them. In terms of condemning particular use cases (or deciding not to), I'm more trying to represent…

> because these institutions protect them. All I am saying is that you could replace your antagonists in that line with "journalists" and you'd be like, "no wait, that's not true," and you'd be as wrong about journalists as anyone else. Either there are some powerful institutions protecting journalists too, OR Tor is powerful enough to protect journalists. If it's not good enough for journalists, why bother? If it's…

I would absolutely agree that there's journalists who get significant power and protection from their proximity to major institutions and centres of power. Tor is useful for protecting journalists in situations where they don't have access to that kind of protection. I would agree as you say that's also the case for people that it protects who want to commit really awful forms of harm (who might not have access to this kind of protection). But I'd argue that - in most cases - the majority of really serious and widespread forms of harm are able to exist because of their proximity to different kinds and systems of power. That's not always the case - and these systems of power can compete with one another - but I think it generally holds.

And given that the vast majority of online crime of all kinds isn't anonymous but goes entirely un-enforced against by law enforcement, I would argue that Tor's efforts to distribute power online make relatively little impact on the kinds of crime and harm we see online compared to a lot of other infrastructures built on top of the Internet. I've generally found the more I do this kind of research, the less convinced I am by technical fixes to major social problems - I don't think Tor is a 'fix' to the problem of power, but I think it opens up the battleground a bit for more different (and possibly more hopeful) kinds of future Internet to be built and asserted, that look less like the locked down and centralised versions we're being pitched just now. But I take your points and appreciate you engaging with the arguments in the book.

Actually the relay community is pretty diverse - they have some colourful characters but actually a lot of them are just IT professionals, activists, and people working for libraries or universities. They have come up with some ways (which I talk about in the book) of making them much less likely to get hassle for running an exit - and generally most exit relay operators proceed just fine.

Re: Tor: From the Dark Web to the Future of Privacy

#32
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

There are no incentives for running a Tor node except altruism and the perhaps nebulous claim that by doing so you will be making the network better. There is nothing stopping a state actor controlling a large percentage of nodes thus increasing the likelihood that your anonymous communications are nothing of the sort.

You can connect through a locally running node, which reduces latency to some degree.

Re: Tor: From the Dark Web to the Future of Privacy

#34
post #13
post #5

Earlier quoted context omitted.

I assume that TOR is vulnerable to the 51% attack? If so I would imagine that state actors have the ability to spin up a million containers each hosting a node and easily take control (or at least be able to start tracing connection from entry to exit node). However Im sure this would be immediately obvious (unless they have been slowly doing this since the begining of TOR)

IIRC there is at least one known case where a moderately major criminal was let go rather than the government disclosing how they got the evidence on him. The assumption has been that they had a way of compromising TOR that they didn't want to reveal.

One implication of that - make sure there's no available means of parallel construction, and it's ok if they catch you in some way they don't want to reveal. As long as you're not valuable enough, that is.

Re: Tor: From the Dark Web to the Future of Privacy

#35
post #28

Earlier quoted context omitted.

People can do things altruistically - there doesn't always need to be a bitcoin-style monetary incentive. Lots of people run exit nodes because they believe in privacy and freedom of information. That said, you're absolutely right about large entities being able to control a large number of nodes, which is why a great number of nodes are controlled by governments trying to do so and also prevent foreign adversaries f…

> People can do things altruistically - there doesn't always need to be a bitcoin-style monetary incentive. For a few years Oniontip [1] allowed tipping Tor relay operators with Bitcoin. In my opinion that was a quite nice combination of technologies, as it allowed to anonymously tip operators of a service providing anonymity on the internet. [1]: https://github.com/DonnchaC/oniontip

Bit coin is not anonymous. It is literally a ledger of every transaction ever made. Monero is what you want if you value anonymity.

Re: Tor: From the Dark Web to the Future of Privacy

#36

Earlier quoted context omitted.

What are your thoughts on the integrity of the network against state actors?

There's a lot in the book about this - it depends what you mean. Tor has a lot of social and technical design elements that try as best they can to minimise this risk. It would be pretty hard for intelligence services to compromise the Tor organisation in ways that meant they were deploying malicious code, for example. Plus, the way it's grown over the years has also given them some protections. In terms of deanonymi…

The scenario that I understand is more plausible, is when state level actors might control some large fraction of tor nodes. Not that they have visibility into the entire internet (not ruling that out, though). The rule of thumb I've heard is that if you're a sufficiently valuable target, best assume Tor is compromised.

Re: Tor: From the Dark Web to the Future of Privacy

#37
post #16

It seems, at the beginning of the 90s there were a lot of expectations in regard to DC-nets, considered to be a way better alternative to remailers of the time [1]. At least that's my impression after reading Tim May's FAQ (The Cyphernomicon) [2]. Any progress on this front? [1]: https://en.wikipedia.org/wiki/Anonymous_remailer [2]: https://hackmd.io/@jmsjsph/TheCyphernomicon

This is a question I always find really interesting. There are still a lot of alternative systems circulating - often in the mid-latency space - which aim to solve design issues of Tor. Someone releases something intended to be a Tor killer every few years, but they rarely last. Tor still remains the only anonymity solution currently operating at global scale without depositing all your trust in e.g. a VPN provider, partly due to network effects (the installed size of the user base is its own protection, so any competitor system is going to perform worse at the outset regardless), the relative lack of tolerance for anything but the lowest possible latency, highest possible usability system for almost all users, and Tor's lasting success in establishing itself culturally as a global brand that can appeal differently to very different user groups. Tor's devs have also been very good at modularising and standardising the tech so it's been great at getting itself incorporated at the ground level of other technologies - and upcoming changes are only going to make that more the case. I do think that there's a good chance for other systems and models to take off that make different design decisions, but they would have a lot of economic, technical, and cultural barriers to circumvent. Not all of them are to do with the theoretical security of the system - for example, DC-net designs were always traditionally quite vulnerable to Denial of Service attacks via collision, and some of the best attacks against anonymity systems can use 'higher security' properties against them. There's a discussion of some of this in Chapters 4, 5, and 6 of the book if it's of interest - also a huge amount written about this by scholars in PETS, WEIS, and other conferences (and blogs, papers, textbooks etc. in cryptospace).

Re: Tor: From the Dark Web to the Future of Privacy

#38

> Wealth and power, the complicity of institutions, governments and communities that ignore the rights of children and disbelieve and disempower them—all of these provide far better privacy protections for child sex abusers than the Tor relay network ever could. Either the technology is good enough to make people anonymous despite their lack of wealth, power, complicity of institutions, or it's not. It can't be a wea…

Those are fair points. I would argue that it's not the tech that's weak, but that the protection that powerful people get from institutions, local networks, status in their communities etc. often give them so much access to practical power that they essentially don't need anonymity - because these institutions protect them. In terms of condemning particular use cases (or deciding not to), I'm more trying to represent…

>Obviously sometimes when people argue that they just have an issue with feminist values - sometimes it is definitely disingenuous. But I think there was a wider moment in the Tor community - in which a lot of people were concerned about the transition to a much more professional NGO, more strongly aligned with liberal, 'digital democracy' visions of US geopolitics, and away from a more chaotic and anarchic coalition. While I think there was a clear need for Tor to change and this was as much about its place amid wider changes in the landscape of digital rights, US tech, and hacker politics as anything else, it does give us a way (I think) of understanding the conflicts and choices that might emerge in Tor and other privacy enhancing infrastructures in the future.

Yes, you need to be a toxic slug or you will be eaten.

I was around for the transition and it was anything but clean. The only reason why tor didn't implode like women who code recently did is that it has a clear core product which the old developers kept chugging along despite the best efforts of the new 'professionals'.

Re: Tor: From the Dark Web to the Future of Privacy

#39
post #4

One thing I'm curious about Tor: What are the incentives for running a node? If there are no monetary incentives, then how does it achieves decentralization? Also, what stops a malicious actor with enough resources (a government) from controlling a big portion of the network?

Couldn't running an exit node be a cover for other activity? One that provides a reasonable doubt as to whether it was the operator or some other actor who did something unsavory from an IP address?
Post reply on HN