Tor best practices
21–30 of 59 posts
Re: Tor best practices
#22It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".
Re: Tor best practices
#23It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".
"doing some shady shit" Or he is a freedom fighter)
"For personal reasons, I do not browse the web from my computer. (I also have not net connection much of the time.) To look at page I send mail to a demon which runs wget and mails the page back to me. It is very efficient use of my time, but it is slow in real time."
Re: Tor best practices
#24It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".
Re: Tor best practices
#25"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. If you are using tor and you are using a web browser as your primary means of communication AND YOU REQUIRE SAFTEY you have already made…
It's not exactly fanboyism that makes security-conscious people prefer Linux. In fact, anybody with even a basic understanding of infosec knows that Windows should be considered wide open: Microsoft has backdoors, they give the NSA backdoors, and their code isn't open to peer review. Moreover, the Tor Freedom Host attack only exploited Firefox on Windows.
> Just using tails or whonix and being super paranoid...because security...is kind of a shit lifestyle decision.
Don't you think this is a little rude? Or even just presumptive?
Re: Tor best practices
#26Earlier quoted context omitted.
> People can still compare when you're using your internet on Tor and when you doing activities online (on Tor) Ok, so what is the threat model in this case? (really want to understand)
Logs subpoenaed from your ISP show that you were using Tor between 3:10 and 5:23 PM on 02/05/2012. Logs from forensic analysis of a breakin to EvilCorp show that the attacker came in from Tor and was downloading secret data from 3:10 to 5:23 PM on the same day. Not enough to prove anything, but there's definitely some circumstantial evidence there.
Re: Tor best practices
#27Earlier quoted context omitted.
Tor is far from perfect. Even if Tor does everything it's meant to. People can still compare when you're using your internet on Tor and when you doing activities online (on Tor). What this person is saying does make sense.
"using your internet on Tor" and "doing online activities (on Tor)" sound like the same thing to me. But this whole article sounds to me like the author's expecting people to only ever use Tor when they want to hide something. What we should be doing is encouraging everyone to use Tor all the time for everything, delays be damned. That totally obliterates any correlative analysis.
Re: Tor best practices
#28"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. If you are using tor and you are using a web browser as your primary means of communication AND YOU REQUIRE SAFTEY you have already made…
> The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. It's not exactly fanboyism that makes security-conscious people prefer Linux. In fact, anybody with even a basic understanding of infosec knows that Windows should be considered wide open: Microsoft has backdoors, they give the NSA backdoors, and their code isn't…
Re: Tor best practices
#29Earlier quoted context omitted.
Logs subpoenaed from your ISP show that you were using Tor between 3:10 and 5:23 PM on 02/05/2012. Logs from forensic analysis of a breakin to EvilCorp show that the attacker came in from Tor and was downloading secret data from 3:10 to 5:23 PM on the same day. Not enough to prove anything, but there's definitely some circumstantial evidence there.
But if you use Tor for all of your day-to-day browsing, in strict contrast with the OP's recommendation, then there's not such a glaring correlation.
Re: Tor best practices
#30"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. If you are using tor and you are using a web browser as your primary means of communication AND YOU REQUIRE SAFTEY you have already made…
> The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. It's not exactly fanboyism that makes security-conscious people prefer Linux. In fact, anybody with even a basic understanding of infosec knows that Windows should be considered wide open: Microsoft has backdoors, they give the NSA backdoors, and their code isn't…
"security-conscious people prefer Linux"...That's kind of a sweeping statement. What does security conscious even mean?
To me it sounds like this..."People who talk about security a lot use Linux by and large"..."but some of them are really partial to OpenBSD"..."and lots of Windows security experts really use Windows a lot."
I say that its a shit lifestyle decision because what is it accomplishing? You use this really restricted platform to make sure that people can't track you doing ??? What exactly? Communicating with your team of spy's??? Downloading midget porn??? Why do you think that you can have a single workstation that's good for every security corner case? What in the history of computer security makes you think that is a good idea or even desirable?
Let's take the example of the Iranian dissident trying to avoid the oppressive badies in their weird ass government...what does tails or Linux buy you? You are better off with the "throw away laptop" plan using good opsec and running tor from public places. Don't use it for anything but tor and tweeting your pics of black helmeted assholes. Get a new one as soon as possible. Rotate them with other people. The OS means next to nothing.
People keep conflating tor's uses with every possible InfoSec edge case. The dissident has different needs than a guy trying to make sure that the NSA doesn't catch him posting documents. The whistleblower has different needs than the guy buying drugs.
In all cases applying some critical thinking about what you are trying to do is a bigger exercise than "Winblows is the suxor at securitehz!"
Unix doesn't have a monopoly on security. I'm not saying windows does, but Unix people are kind of crazy about their pet platform.