Live data from Hacker News

Partnering with Mozilla

blog.torproject.org

1–10 of 104 posts

Re: Partnering with Mozilla

#4
More relays? That's great, but why not exit nodes?

Mozilla certainly has the manpower and infrastructure to operate a bunch of exit nodes, and if they have any legal qualms about it, hey, they just partnered with an EFF project, right?

Re: Partnering with Mozilla

#5

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

Re: Partnering with Mozilla

#6
This sort of this is pretty exciting. Now that users are aware of NSA hijinks, and are familiar with the Privacy modes of their current browsers, I'd like to see Mozilla move towards a "Super Privacy" mode where they route over a built-in Tor client.

Of course, the dream would be to have all Firefox clients run Tor relay nodes out of the box, backed by Mozilla-supported exit nodes.

Re: Partnering with Mozilla

#7
post #4

More relays? That's great, but why not exit nodes? Mozilla certainly has the manpower and infrastructure to operate a bunch of exit nodes, and if they have any legal qualms about it, hey, they just partnered with an EFF project, right?

[deleted]

Re: Partnering with Mozilla

#8
One major challenge:

Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked documents say that use of security services, including VPNs and I think Tor also, causes the data to be retained by the NSA for future decryption.

How can Mozilla and their partners provide confidentiality in a way that increases end-user security, rather than attracting further scrutiny or, far worse, providing dangerously false assurances? The answer cannot depend on end users understanding the technology or subtle tradeoffs; the vast majority will never understand.

One thought: Route all Firefox users through Tor relays by default, creating some security-through-obscurity. There are problems with that, of course, including the blacklisting of Tor relays from many sites.

Re: Partnering with Mozilla

#9

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

Based on what info?

I'm really not sure why I'm being downvoted (or even killflagged). The Mozilla Foundation is a US based organisation and has no choice in the matter if the feds come knocking for PRISM signup.

Re: Partnering with Mozilla

#10
post #5

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

Lavabit could do it because they were a small shop (under 10 employees). Do you really think Mozilla is going to pull the pin with over 1000 employees?

More likely would be that they relocate. But relocating over 1000 people would be a massive feat.

Post reply on HN