Live data from Hacker News

Partnering with Mozilla

blog.torproject.org

21–30 of 104 posts

Re: Partnering with Mozilla

#21
post #19
post #5

Earlier quoted context omitted.

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

I don't believe they would simply close in that case; I strongly believe that they would instead choose to remain open under the logic that compromised but still working for user security / web "openness" is superior to folding and losing a force which aims to work for the "greater good". I believe this given their past choices in things like H264 and EME. Given that, though, I also believe that enough smart people a…

regarding H264 and EME, there are legitimate reasons for them having conceded on those fronts. Content providers do have a legitimate interest in protecting copyrighted work. Likewise, H264 is widely deployed and is already a sunk cost for most consumers and migrating away from it will take at least a decade, it was never going to work to forcefully go cold turkey; not everyone can pull an Apple and yank Flash support.

while those choices certainly limit user freedom (as in choice), they do not compromise user security (assuming EME is properly sandboxed, etc)

i don't think they would just up and close, they'd likely just sunset/curtail the services which would be subject to interception. in Lavabit's case, that was the entire business.

Re: Partnering with Mozilla

#22

Earlier quoted context omitted.

Hopefully they simply don't back an architecture where the only option is to pull the plug.

the only type of architecture that is resistant to this would have to be distributed. for anything centralized and under control of a US company, the US laws can compel them to install intercept devices. sadly, not everything can be distributed, there will be centralization somewhere.

So people should start using it and hope that when the US compels them to do something, it is done in a way where Mozilla can resist it politically?

Re: Partnering with Mozilla

#23
post #8

One major challenge: Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked…

>One thought: Route all Firefox users through Tor relays by default, creating some security-through-obscurity. There are problems with that, of course, including the blacklisting of Tor relays from many sites.

Sure this would accomplish that goal, but it's extremely unpractical. The Tor network is slow enough as it is, add millions more people and it'll grind to a halt. Plus all the issues of sites that rely on IP addresses for fraud detection and moderation (banning spammers, for example).

Re: Partnering with Mozilla

#24
post #13

Hm. I'm thinking Mozilla may be a modern day NRA. The point of the right to bear arms is to protect the people from a government engaging in tyranny. The point of TOR is ideally the same. Maybe it's time to classify encryption as a weapon again.

That's sort of true, except guns are used to assault while anonymity is used to defend.

Re: Partnering with Mozilla

#25
post #13

Hm. I'm thinking Mozilla may be a modern day NRA. The point of the right to bear arms is to protect the people from a government engaging in tyranny. The point of TOR is ideally the same. Maybe it's time to classify encryption as a weapon again.

That's sort of true, except guns are used to assault while anonymity is used to defend.

Anonymity can be used to assault, too.

Re: Partnering with Mozilla

#26
post #8

One major challenge: Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked…

Routing all Firefox users through Tor relays by default would be madness.

* It would make Firefox slow.

* It would place a tremendous load on the Tor network.

* It would defeat content filtering (which includes blocking malware) on enterprise networks.

* It would expose users to traffic interception and manipulation who wouldn't otherwise be so exposed.

Re: Partnering with Mozilla

#27

Earlier quoted context omitted.

the only type of architecture that is resistant to this would have to be distributed. for anything centralized and under control of a US company, the US laws can compel them to install intercept devices. sadly, not everything can be distributed, there will be centralization somewhere.

So people should start using it and hope that when the US compels them to do something, it is done in a way where Mozilla can resist it politically?

it's hard to answer this with a blanket statement because it's one company that does many things and builds many products. i'm not sure what the law says about requiring a company to continue to operate a service just for the sake of intercepting traffic, when the morals/mission of the company would otherwise terminate the service. i'd be interested to see if something like this has been tested in court.

the general rule of thumb is, don't base critical parts of your business or personal life on third-party cloud products that may go away for whatever reason, without your control and without notice. this includes Google's random termination of APIs, encrypted email services, etc. have a plan B if for some reason the Tor relays need to be suddenly taken offline, forever.

Re: Partnering with Mozilla

#29
post #18
post #13

Hm. I'm thinking Mozilla may be a modern day NRA. The point of the right to bear arms is to protect the people from a government engaging in tyranny. The point of TOR is ideally the same. Maybe it's time to classify encryption as a weapon again.

Considering TOR was paid for by the US government I think your concerns might be misplaced. That or TOR is a massive Honneypot and .... NO CARRIER

Several of the rifles that individuals in the US can own were also developed by the US government!

Re: Partnering with Mozilla

#30
post #5

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

If you really have to trust Mozilla here someone is doing something wrong.

Presumably these hosts will be part of a relay family and so tor will not select multiple of them in constructing a circuit.

When it comes down to it no matter how trustworthy mozilla has been in the past, any service they offer could be compromised going forward in a multitude of ways. This is why its important that systems and software be designed to be secure even without trust. (Then, add in some trust for good measure too).

Post reply on HN