Live data from Hacker News

Partnering with Mozilla

blog.torproject.org

11–20 of 104 posts

Re: Partnering with Mozilla

#11
post #5

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

> mozilla, like few other companies, has my full faith that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

That trust is an exceptional asset, a unique competitive advantage for Mozilla. None of their for-profit[1] competitors can hope to compete in that area and I think it's especially valuable now that users are becoming aware of privacy and when the behavior of the competition often is so egregious. Mozilla has a chance to solidify their brand for the long term as the IT provider users can trust. If they can do that, IMHO they have a leg up in every market.

[1] I know Mozilla Corp. is for-profit, but profit is not their primary objective.

Re: Partnering with Mozilla

#12
post #5

Earlier quoted context omitted.

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

Lavabit could do it because they were a small shop (under 10 employees). Do you really think Mozilla is going to pull the pin with over 1000 employees? More likely would be that they relocate. But relocating over 1000 people would be a massive feat.

how they handle their moral and legal obligations to 1,000+ people is up to them and i am sure those 1,000 people will be able to get as much assistance as they need to hold them over. 1,000 people keeping their jobs is statistically insignificant to the tens (hundreds?) of millions of compromised, faithful users. i dont think it would even be a question for them if the circumstances allowed for no other options. i believe their users would fully expect them to do this.

"I really wish Ladar Levison handed NSA the SSL keys so I could keep my email"

-- no Lavabit user, ever.

Re: Partnering with Mozilla

#13
Hm. I'm thinking Mozilla may be a modern day NRA.

The point of the right to bear arms is to protect the people from a government engaging in tyranny. The point of TOR is ideally the same. Maybe it's time to classify encryption as a weapon again.

Re: Partnering with Mozilla

#14
post #5

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

Hopefully they simply don't back an architecture where the only option is to pull the plug.

Re: Partnering with Mozilla

#15

Earlier quoted context omitted.

Based on what info?

I'm really not sure why I'm being downvoted (or even killflagged). The Mozilla Foundation is a US based organisation and has no choice in the matter if the feds come knocking for PRISM signup.

Another disturbing aspect is that TOR itself is funded by the US govt. It is not so much of a contradiction. It is very likely that 3 letter agencies actively use and benefit from TOR backed services. But should the cost benefit balance tilt the other way, the money stream will probably disappear and/or its security compromised.

Re: Partnering with Mozilla

#16
post #8

One major challenge: Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked…

The Tor Browser Bundle already comes with a bunch of hacks to make users more difficult to track. I suppose they could improve on that until you're no longer identifiable on something like EFF's Panopticlick [1] or Samy Kamkar's Evercookie [2].

For example, isolate each tab, nuke all tracking cookies by default, clear all local storage at a regular interval, access different sites using different circuits, and only allow JS to access a minimum of information about the system. Even better, expose fake, generic, but slightly varying lists of system fonts, plugins, and other information. (Fake information is better than disallowing access altogether, because the latter looks too suspicious.)

Of course, none of this will keep you anonymous if you log into Facebook using Tor... but at least the browser could make it extremely difficult for anyone to find out that the person who is visiting unrelated-website.com is the same person who just logged into Facebook. Automatically switching circuits when you visit a new site would probably do wonders in this regard, though I'm not sure how well Tor can handle that.

[1] https://panopticlick.eff.org/

[2] http://samy.pl/evercookie/

Re: Partnering with Mozilla

#17
post #5

Earlier quoted context omitted.

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

Hopefully they simply don't back an architecture where the only option is to pull the plug.

the only type of architecture that is resistant to this would have to be distributed. for anything centralized and under control of a US company, the US laws can compel them to install intercept devices. sadly, not everything can be distributed, there will be centralization somewhere.

Re: Partnering with Mozilla

#18
post #13

Hm. I'm thinking Mozilla may be a modern day NRA. The point of the right to bear arms is to protect the people from a government engaging in tyranny. The point of TOR is ideally the same. Maybe it's time to classify encryption as a weapon again.

Considering TOR was paid for by the US government I think your concerns might be misplaced. That or TOR is a massive Honneypot and ....

NO CARRIER

Re: Partnering with Mozilla

#19
post #5

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

I don't believe they would simply close in that case; I strongly believe that they would instead choose to remain open under the logic that compromised but still working for user security / web "openness" is superior to folding and losing a force which aims to work for the "greater good". I believe this given their past choices in things like H264 and EME.

Given that, though, I also believe that enough smart people are in Mozilla that they would try to prevent themselves from being in a position where they would be a target such that they would face the dilemma. Which might be why they're only hosting middle relays, and not exits or guards :)

Re: Partnering with Mozilla

#20
post #6

This sort of this is pretty exciting. Now that users are aware of NSA hijinks, and are familiar with the Privacy modes of their current browsers, I'd like to see Mozilla move towards a "Super Privacy" mode where they route over a built-in Tor client. Of course, the dream would be to have all Firefox clients run Tor relay nodes out of the box, backed by Mozilla-supported exit nodes.

As hackuser says elsewhere, Tor is not really a fire-and-forget security solution. My understanding is that in order to use it without compromising yourself you need to have a fairly sophisticated understanding of its limitations.
Post reply on HN