Live data from Hacker News

Partnering with Mozilla

blog.torproject.org

31–40 of 104 posts

Re: Partnering with Mozilla

#31
post #5

I'm guessing Mozilla's Tor middle relays will soon be a part of PRISM

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

>pull a Lavabit

So, silently comply with warrants and other requests until a high-profile case comes along, then refuse to cooperate until a judge gets you to hand over everyone's data and your master keys, then turn that into a big PR show? OK.

Re: Partnering with Mozilla

#32
post #19

Earlier quoted context omitted.

I don't believe they would simply close in that case; I strongly believe that they would instead choose to remain open under the logic that compromised but still working for user security / web "openness" is superior to folding and losing a force which aims to work for the "greater good". I believe this given their past choices in things like H264 and EME. Given that, though, I also believe that enough smart people a…

regarding H264 and EME, there are legitimate reasons for them having conceded on those fronts. Content providers do have a legitimate interest in protecting copyrighted work. Likewise, H264 is widely deployed and is already a sunk cost for most consumers and migrating away from it will take at least a decade, it was never going to work to forcefully go cold turkey; not everyone can pull an Apple and yank Flash suppor…

>Content providers do have a legitimate interest in protecting copyrighted work

Except DRM in the browser doesn't really accomplish that, does it? Hit The Pirate Bay or Google up a torrent and done. Things like Netflix DRM are only one step above HDCP.

Re: Partnering with Mozilla

#33
post #30
post #5

Earlier quoted context omitted.

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

If you really have to trust Mozilla here someone is doing something wrong. Presumably these hosts will be part of a relay family and so tor will not select multiple of them in constructing a circuit. When it comes down to it no matter how trustworthy mozilla has been in the past, any service they offer could be compromised going forward in a multitude of ways. This is why its important that systems and software be de…

in an ideal world, yes, we should require 0 trust; i don't think we well ever live in that world, it is prohibitively expensive and impractical.

Re: Partnering with Mozilla

#34

Earlier quoted context omitted.

So people should start using it and hope that when the US compels them to do something, it is done in a way where Mozilla can resist it politically?

it's hard to answer this with a blanket statement because it's one company that does many things and builds many products. i'm not sure what the law says about requiring a company to continue to operate a service just for the sake of intercepting traffic, when the morals/mission of the company would otherwise terminate the service. i'd be interested to see if something like this has been tested in court. the general…

I still don't see why someone worried about the US government would even start using a service where the best outcome of a warrant is that the service gets shut down.

Re: Partnering with Mozilla

#35
post #4

More relays? That's great, but why not exit nodes? Mozilla certainly has the manpower and infrastructure to operate a bunch of exit nodes, and if they have any legal qualms about it, hey, they just partnered with an EFF project, right?

What I don't understand is why Tor doesn't bundle their relays with their clients and have a network that scales better naturally, like I2P, and instead relies on people hosting their own, hopefully high bandwidth, relays.

Re: Partnering with Mozilla

#37
post #5

Earlier quoted context omitted.

mozilla, like few other companies, has my full faith and confidence that they would pull a Lavabit and close up shop before letting something like this completely erode their users' trust.

>pull a Lavabit So, silently comply with warrants and other requests until a high-profile case comes along, then refuse to cooperate until a judge gets you to hand over everyone's data and your master keys, then turn that into a big PR show? OK.

> then turn that into a big PR show

if protecting whistle-blowers requires a PR show, i'll buy a front-row seat and pass me that popcorn. i believe what happened with the snowden request was not the same as other requests, obvious why in retrospect. http://www.wired.com/2013/09/lavabit-snowden-pen-register/

> So, silently comply with warrants and other requests

so are you suggesting, for the purpose of avoiding accusations of hypocrisy, all businesses should either comply unconditionally or close immediately and relocate to another country? what he did was unorthodox and perhaps somewhat PR motivated, but he did ultimately close his primary (only?) source of income on moral grounds. i'm not sure how much shit-slinging he deserves here.

anyhow, i think you took the analogy too literally.

Re: Partnering with Mozilla

#38
post #4

More relays? That's great, but why not exit nodes? Mozilla certainly has the manpower and infrastructure to operate a bunch of exit nodes, and if they have any legal qualms about it, hey, they just partnered with an EFF project, right?

What I don't understand is why Tor doesn't bundle their relays with their clients and have a network that scales better naturally, like I2P, and instead relies on people hosting their own, hopefully high bandwidth, relays.

I'm guessing that hosting relays could get people in trouble in some jurisdictions, even if they're just middle relays and not exit nodes.

Since the goal of Tor is to let people use the internet safely in such jurisdictions -- in fact, especially in such jurisdictions -- some might consider the loss of relay bandwidth an acceptable compromise.

Re: Partnering with Mozilla

#39

Earlier quoted context omitted.

regarding H264 and EME, there are legitimate reasons for them having conceded on those fronts. Content providers do have a legitimate interest in protecting copyrighted work. Likewise, H264 is widely deployed and is already a sunk cost for most consumers and migrating away from it will take at least a decade, it was never going to work to forcefully go cold turkey; not everyone can pull an Apple and yank Flash suppor…

>Content providers do have a legitimate interest in protecting copyrighted work Except DRM in the browser doesn't really accomplish that, does it? Hit The Pirate Bay or Google up a torrent and done. Things like Netflix DRM are only one step above HDCP.

regardless of how misguided their attempts are, doing nothing is a non-option for studios, right? what alternatives are there? there are none - those who make the content make the rules, it's something i'm confident will not change.

https://hacks.mozilla.org/2014/05/reconciling-mozillas-missi...

anyways, this is off-topic.

Re: Partnering with Mozilla

#40
post #8

One major challenge: Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked…

It is a tricky issue, but I can see a good argument for increasing the amount of traffic going through TOR, even if much of it was from users without proper OPSEC.

As with all security, it is an education issue; just as "Private Mode" warns users that they might be tracked by ISPs or other agents, "Super-private mode" would have to warn users that supplying identifying information would jeopardize their privacy.

Post reply on HN