Live data from Hacker News

Tor best practices

digital-era.net

51–59 of 59 posts

Re: Tor best practices

#51

Earlier quoted context omitted.

What do you need Windows for anyway? Especially in a "secure computing" context, modern distros are cheaper, easier and quicker to install than Windows, and yes, often more secure. Plus, learning GNU/Linux will make you a better programmer and a more capable team player. What do you have to lose?

Learning Linux makes you a better programmer? That's what I'm talking about in a nutshell. "Learning GNU/Linux" doesn't make one a better programmer. I'm not even sure how that's supposed to work...you know that there are really good programmers that use other platforms, right?

Ever heard the term, "don't knock it til you try it"? What do you have to lose by trying free operating systems? It costs nothing to run GNU/Linux in VirtualBox on Windows, and learning to interact with your machine from the command line will expand your skillset and your horizons, making you a better programmer and more valuable team player. Regardless, you're bashing people for using free operating systems in a security context, which is just asinine. This is not the holy war you're making it out to be.

Re: Tor best practices

#54

Earlier quoted context omitted.

>"1. don't use windows"...I realize how unpopular it is to question the groupthink on this site but this strikes me as simplistic. The public takedowns related to tor have been more about firefox than windows. But I get that Linux fans like to think that this is their sole bailiwick. The OS provides a number of security mechanisms which make exploitation harder, Windows' reputation for security (or lack thereof) is s…

Windows has DEP and ASLR. They are actually pretty much on par with each other from a TLA standpoint. There are configuration issues that affect security that should be taken into account if you have high security needs. Its not a capabilities issue.

Is there any equivalent of AppArmor on Windows? You can lock down the capabilities of an app pretty hardcore on Linux.

Re: Tor best practices

#55
post #54

Earlier quoted context omitted.

Windows has DEP and ASLR. They are actually pretty much on par with each other from a TLA standpoint. There are configuration issues that affect security that should be taken into account if you have high security needs. Its not a capabilities issue.

Is there any equivalent of AppArmor on Windows? You can lock down the capabilities of an app pretty hardcore on Linux.

Sandboxie?

Re: Tor best practices

#56

Earlier quoted context omitted.

Learning Linux makes you a better programmer? That's what I'm talking about in a nutshell. "Learning GNU/Linux" doesn't make one a better programmer. I'm not even sure how that's supposed to work...you know that there are really good programmers that use other platforms, right?

Ever heard the term, "don't knock it til you try it"? What do you have to lose by trying free operating systems? It costs nothing to run GNU/Linux in VirtualBox on Windows, and learning to interact with your machine from the command line will expand your skillset and your horizons, making you a better programmer and more valuable team player. Regardless, you're bashing people for using free operating systems in a sec…

Do you honestly think that I have never tried Linux? Seriously? The first time I installed Linux I had to download the floppy images over a 2400 baud modem connection to a bulletin board.

I'm not bashing people for using Linux...I'm saying that its not good security to say..."Linux is secure"...and not review your security needs from the standpoint of what you are actually trying to accomplish. I'm not making it out to be a holy war...I'm saying that people are just accepting that "Linux is more secure" on blind faith.

Re: Tor best practices

#57
post #47
post #38

While reading advice like those in the article, they seem to always leave out the most central aspect of security - the threat model. Doing some guessing, the following threats are mitigated by the article: • An attacker has access to zero-day vulnerabilities to the software running on your device¹. • You are storing non-Tor files on your device that can be used to build a profile against you. That or you are running…

• If you rent time at virtual hardware, the real hardware owners can see everything you do. Reminder: the same goes for all your favorite hosted-because-we're-too-lazy-or-inept-to-run-it-ourselves services too. It still amazes me thousands of high profile companies just give all their communications to Google for free.

> It still amazes me thousands of high profile companies just give all their communications to Google for free.

No, they even pay for it.

Re: Tor best practices

#58
post #54

Earlier quoted context omitted.

Windows has DEP and ASLR. They are actually pretty much on par with each other from a TLA standpoint. There are configuration issues that affect security that should be taken into account if you have high security needs. Its not a capabilities issue.

Is there any equivalent of AppArmor on Windows? You can lock down the capabilities of an app pretty hardcore on Linux.

That's actually the new security model that Metro apps use. They are sandboxed by default with a declarative privileges model. I think its called AppContainer?

Here's a blog post: http://recxltd.blogspot.com/2012/03/windows-8-app-container-...

Re: Tor best practices

#59
post #24
post #21

It looks like author of this article is doing some shady shit. Using TOR and moving so much in different locations O_o Seems like his very paranoid. I think he forgot about "Faraday cage".

The only real reason people use Tor at all is for shady shit. They'll deny it all they want and bullshit on about "freedom", but not even Stallman is this autistic. Come on.

So "downloading it to have a look" is now "shady shit"?
Post reply on HN