Live data from Hacker News

Partnering with Mozilla

blog.torproject.org

41–50 of 104 posts

Re: Partnering with Mozilla

#41

Earlier quoted context omitted.

So people should start using it and hope that when the US compels them to do something, it is done in a way where Mozilla can resist it politically?

it's hard to answer this with a blanket statement because it's one company that does many things and builds many products. i'm not sure what the law says about requiring a company to continue to operate a service just for the sake of intercepting traffic, when the morals/mission of the company would otherwise terminate the service. i'd be interested to see if something like this has been tested in court. the general…

Company morals, mission statements, constitutions etc are marketing material and not law. If the law requires a company to comply but their mission statement goes against this, the law will win every time.

Re: Partnering with Mozilla

#42
post #30

Earlier quoted context omitted.

If you really have to trust Mozilla here someone is doing something wrong. Presumably these hosts will be part of a relay family and so tor will not select multiple of them in constructing a circuit. When it comes down to it no matter how trustworthy mozilla has been in the past, any service they offer could be compromised going forward in a multitude of ways. This is why its important that systems and software be de…

in an ideal world, yes, we should require 0 trust; i don't think we well ever live in that world, it is prohibitively expensive and impractical.

At least Mozilla doesn't have a 'business model' which is strongly dependant on you handing your data over to them, or other opaque/closed activities or software.

Re: Partnering with Mozilla

#43
post #16
post #8

One major challenge: Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked…

The Tor Browser Bundle already comes with a bunch of hacks to make users more difficult to track. I suppose they could improve on that until you're no longer identifiable on something like EFF's Panopticlick [1] or Samy Kamkar's Evercookie [2]. For example, isolate each tab, nuke all tracking cookies by default, clear all local storage at a regular interval, access different sites using different circuits, and only a…

The Tor Browser developers have all of this as an explicit goal:

https://www.torproject.org/projects/torbrowser/design/

They still have more work to do to get there, of course -- it's a challenging target!

Re: Partnering with Mozilla

#44

Earlier quoted context omitted.

it's hard to answer this with a blanket statement because it's one company that does many things and builds many products. i'm not sure what the law says about requiring a company to continue to operate a service just for the sake of intercepting traffic, when the morals/mission of the company would otherwise terminate the service. i'd be interested to see if something like this has been tested in court. the general…

Company morals, mission statements, constitutions etc are marketing material and not law. If the law requires a company to comply but their mission statement goes against this, the law will win every time.

i dont think i claimed their morals would allow them to not comply with the law. but a company's past conduct is pretty important to evaluate in the context of how such situations will be handled. i'm unaware of a law that requires companies to continue providing compromised services to their users, for example.

Re: Partnering with Mozilla

#45
post #36
post #25

Earlier quoted context omitted.

Anonymity can be used to assault, too.

...and guns to defend.

Guns are NOT defensive weapons... You could be standing in the Starbucks line with any weapon of your choosing and I can just walk up to you and pull out a pistol and splatter your brains across the counter. No problem...

EDIT - Why is my off-topic comment with an argument being down-voted in a reply to a off-topic statement with no argument is not? There must be a lot of gun lovers on Hacker News...

Re: Partnering with Mozilla

#46

Earlier quoted context omitted.

Based on what info?

I'm really not sure why I'm being downvoted (or even killflagged). The Mozilla Foundation is a US based organisation and has no choice in the matter if the feds come knocking for PRISM signup.

You should assume any packets going over Tor are monitored anyway - use TLS.

Re: Partnering with Mozilla

#47
post #36

Earlier quoted context omitted.

...and guns to defend.

Guns are NOT defensive weapons... You could be standing in the Starbucks line with any weapon of your choosing and I can just walk up to you and pull out a pistol and splatter your brains across the counter. No problem... EDIT - Why is my off-topic comment with an argument being down-voted in a reply to a off-topic statement with no argument is not? There must be a lot of gun lovers on Hacker News...

Because your argument makes no sense at all to the majority (me included). A tool is a tool. Its how you use it that makes it good or bad.

I tend to believe that people who see a tool as one that can only be used in one direction, to be the ones most likely to use it in that direction.

Re: Partnering with Mozilla

#48
post #30

Earlier quoted context omitted.

If you really have to trust Mozilla here someone is doing something wrong. Presumably these hosts will be part of a relay family and so tor will not select multiple of them in constructing a circuit. When it comes down to it no matter how trustworthy mozilla has been in the past, any service they offer could be compromised going forward in a multitude of ways. This is why its important that systems and software be de…

in an ideal world, yes, we should require 0 trust; i don't think we well ever live in that world, it is prohibitively expensive and impractical.

trust is always a fun topic, as people are still unaware of how much stuff they trust today.

Let's say you trust TOR. Great.

Now you have to trust Mozilla's software if thats what you run. Let's say you trust Mozilla too, great.

Now you have to trust your whole OS. Lets say you do that. Great.

Now you have to trust the various devices connected to your computer. Lets say you trust that too. Great.

Now you have to trust the various companies that made all the various chips on your main bus, CPU. And the RAM and many other components. And don't forget the dynamically loadable firmwares running on them.

Good luck with that!

[note: this might have needed to be a reply to the parent post]

Re: Partnering with Mozilla

#49
post #20
post #6

This sort of this is pretty exciting. Now that users are aware of NSA hijinks, and are familiar with the Privacy modes of their current browsers, I'd like to see Mozilla move towards a "Super Privacy" mode where they route over a built-in Tor client. Of course, the dream would be to have all Firefox clients run Tor relay nodes out of the box, backed by Mozilla-supported exit nodes.

As hackuser says elsewhere, Tor is not really a fire-and-forget security solution. My understanding is that in order to use it without compromising yourself you need to have a fairly sophisticated understanding of its limitations.

That could easily change with the help of a well funded team like Mozilla.

Re: Partnering with Mozilla

#50
post #8

One major challenge: Using Tor, end users can easily and unintentionally compromise their confidentiality by disclosing information explicitly (e.g., their email logon) or implicitly (habits, browser fingerprints, and other identifiers); it takes discipline to remain anonymous on Tor and even technically skilled hidden service operators, with reason to be paranoid about illegal businesses, fail to do it. Also, leaked…

How about just allowing all firefox users to access .onion sites securely by default?
Post reply on HN