Live data from Hacker News

Deploying Tor Relays

blog.mozilla.org

41–50 of 91 posts

Re: Deploying Tor Relays

#41
This is awesome.

If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project.

Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)

Re: Deploying Tor Relays

#42
post #37

This is, of course, great news. However, it's my impression that there is a surplus of entry and middle nodes, and a serious shortage of exit nodes, especially fast ones. Also, I've read that the geographic diversity of exit nodes is inadequate. I base these comments on discussions on the tor-talk and tor-relays lists, and from posts on the Tor Project blog.

Would it help if an ISP ran a couple of exit nodes plugged into core routers?

Re: Deploying Tor Relays

#43

Earlier quoted context omitted.

> It is plenty safe to run exit nodes ... in someone else's data center. Never, ever in your own home. If you are raided ALL your computers and ancillaries will be seized.

I've ran an exit node in my home for several years and the worst I've seen as a result of it is several DMCA notices and one polite call from the police in another state.

Even if so far everyone has that exact worst case experience, that doesn't mean tomorrow you won't be arrested for somebody viewing illegal material through your exit host. I know people who've sold drugs and never had any problem, it doesn't mean I'm going to start doing it presuming its safe based off their anecdotes.

Re: Deploying Tor Relays

#44
post #6

Neat. Obviously apples and oranges, but between this and Facebook's Tor Hidden Service we're starting to see adoption of real privacy tools among major companies.

> facebook > privacy

There is a diffrence between mostly voluntaryly pushing your own data into facebook and wanting to not be detected when organising political rally.

Re: Deploying Tor Relays

#45

This is awesome. If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)

> If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project.

I run three relays right now. I agree that it's pretty easy to setup, especially on Ubuntu, but the documentation could really use improvement. It makes it sound much harder to setup than it actually is.

To anyone who is thinking of running a relay, here are the basic steps:

1. Add the Tor repo to your package manager [1]

2. Install Tor

3. Edit the config file to set a name, your contact info, bandwidth limit, and exit policy. This is all pretty well documented in the config file.

4. Start Tor (eg `sudo service tor start`)

If you want to run an exit node you should read the Tor docs about the topic and decide which ports to open.[2][3]

1: https://www.torproject.org/download/download-unix.html.en

2: https://trac.torproject.org/projects/tor/wiki//doc/TorExitGu...

3: https://blog.torproject.org/blog/tips-running-exit-node-mini...

Re: Deploying Tor Relays

#46

This is awesome. If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)

We haven't made a decision on either running a hidden service or exits. We do plan to come back and do the analysis and legal review, however we don't have a timeline for this yet. Right now, we're just wading in and will see what we learn.

Re: Deploying Tor Relays

#47
post #30
post #26

Earlier quoted context omitted.

There already is: https://www.torservers.net/

I work at Mozilla, and the folks at Torservers.net were extremely helpful in helping us get up to speed quickly. We're hoping to contribute to the public body of knowledge on how to operate servers efficiently, both in terms of effort and cost.

Great, documentation and design contributions from Mozilla would be as valuable as running nodes. That is something they do well.

Re: Deploying Tor Relays

#48
post #35

Earlier quoted context omitted.

Has that ever been proven? I suspect it's as unproven as the theory that Tor operators are "common carriers" and as liable for the traffic that passes over their connection as an ISP is for the traffic that passes over its connections.

I'd like to suggest https://www.torproject.org/eff/tor-legal-faq.html.en which was written by my colleagues at EFF. (It doesn't mention particular legal theories that may help exit node operators, though I think CDA §230 and DMCA §512 might be among the laws you're thinking of that have historically protected ISPs, since ISPs have resisted being classified as common carriers in the U.S.)

Thanks schoen! This EFF document was invaluable to Mozilla's legal team and helped us get this project to approval in record time.

Re: Deploying Tor Relays

#49
> We chose to make use of our spare and decommissioned hardware. That included a pair of Juniper EX4200 switches and three HP SL170zG6 (48GB ram, 2Xeon L5640, 21Gbps NIC)

In other words, Mozilla has enough money that a 48GB ram machine is otherwise a paperweight...

Re: Deploying Tor Relays

#50
post #46

This is awesome. If you have a VPS spare bandwidth, I encourage you to set up a relay, too. It is very easy to do and a great way to contribute to the Tor project. Is Mozilla planning to set up a hidden service for mozilla.org? I didn't see anything mentioned. The more sites that support hidden services, the less need for exit nodes (which are arguably one of the least secure parts of Tor.)

We haven't made a decision on either running a hidden service or exits. We do plan to come back and do the analysis and legal review, however we don't have a timeline for this yet. Right now, we're just wading in and will see what we learn.

Thanks for the reply!
Post reply on HN